GPG Memory Forensics
ID: 2b6bf8ee-2031-5909-8ee6-c1e3207d97f5
STIX ID: report--2b6bf8ee-2031-5909-8ee6-c1e3207d97f5
Feed Name: Kudelski Security
This report analyzes a Libgcrypt/GPG memory-handling weakness that allowed residual key material and the first eight bytes of passphrases to be recovered from process memory. The authors demonstrate methods to locate GPG cache structures, recover AES key schedules from RAM and fully decrypt cached items, provide Volatility3 plugins as proofs-of-concept, and note the immediate fix in Libgcrypt 1.8.9; exploitation requires access to process or system memory (e.g., forensic dump or local access).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
