Echo: gnupg2: security update to 2.4.9-7+e3

low Tenable Self-Hosted Container Security Plugin ID 473203

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- gpgtar in GnuPG before 2.5.19 can allow file overwrite via crafted data in an archive. When extracting an
untrusted archive with --directory (aka -C) into an existing directory containing a pre-existing symlink,
gpgtar can follow that symlink and create or overwrite a file outside the selected extraction directory.
The write is limited by the extraction user's filesystem permissions. An archive extracted into a fresh
empty directory does not have this risk. (CVE-2026-105712)

Solution

Update the gnupg2 library and its related packages to version 2.4.9-7+e3 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-105712

Plugin Details

Severity: Low

ID: 473203

Version: Revision 1.1

Type: Local

Published: 10/6/2026

Updated: 10/6/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 8.13

CVSS v2

Risk Factor: Low

Base Score: 2.6

Temporal Score: 1.9

Vector: CVSS2#AV:L/AC:H/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2026-105712

CVSS v3

Risk Factor: Low

Base Score: 3.6

Temporal Score: 3.2

Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/6/2026

Vulnerability Publication Date: 10/5/2026

Reference Information

CVE: CVE-2026-105712