The sequoia-openpgp crate 1.13.0 before 1.21.0 for Rust allows an infinite loop of "Reading a cert: Invalid operation: Not a Key packet" messages for RawCertParser operations that encounter an unsupported primary key type.
References
| Link | Resource |
|---|---|
| https://crates.io/crates/sequoia-openpgp | Product |
| https://gitlab.com/sequoia-pgp/sequoia/-/issues/1106 | Exploit |
| https://rustsec.org/advisories/RUSTSEC-2024-0345.html | Third Party Advisory |
| https://gitlab.com/sequoia-pgp/sequoia/-/issues/1106 | Exploit |
Configurations
History
No history.
Information
Published : 2025-07-27 20:15
Updated : 2025-08-06 20:59
NVD link : CVE-2024-58261
Mitre link : CVE-2024-58261
CVE.ORG link : CVE-2024-58261
JSON object : View
Products Affected
sequoia-pgp
- sequoia-openpgp
CWE
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
