logo

GPG Memory Forensics

ID: 2b6bf8ee-2031-5909-8ee6-c1e3207d97f5

STIX ID: report--2b6bf8ee-2031-5909-8ee6-c1e3207d97f5

Feed Name: Kudelski Security

Threat Score
50/100

Date Published: 2022-06-16

Date Updated: 2026-07-22

...
...

This report analyzes a Libgcrypt/GPG memory-handling weakness that allowed residual key material and the first eight bytes of passphrases to be recovered from process memory. The authors demonstrate methods to locate GPG cache structures, recover AES key schedules from RAM and fully decrypt cached items, provide Volatility3 plugins as proofs-of-concept, and note the immediate fix in Libgcrypt 1.8.9; exploitation requires access to process or system memory (e.g., forensic dump or local access).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.