[ubuntu/focal-security] gnupg2 2.2.19-3ubuntu2.5 (Accepted)

Julia Sarris julia.sarris at canonical.com
Mon Jul 7 15:03:08 UTC 2025


gnupg2 (2.2.19-3ubuntu2.5) focal-security; urgency=medium

  * debian/patches/fix-key-validity-regression-due-to-CVE-2025-
    30258.patch:
    - Fix a key validity regression following patches for CVE-2025-30258,
      causing trusted "certify-only" primary keys to be ignored when checking
      signature on user IDs and computing key validity. This regression makes
      imported keys signed by a trusted "certify-only" key have an unknown
      validity (LP: #2114775).

Date: 2025-07-03 14:01:11.216880+00:00
Signed-By: Julia Sarris <julia.sarris at canonical.com>
https://launchpad.net/ubuntu/+source/gnupg2/2.2.19-3ubuntu2.5
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list