{"id":"SUSE-FU-2026:21232-1","summary":"Feature update for libgcrypt, libgpg-error","details":"This update for libgcrypt, libgpg-error fixes the following issues:\n\nUpdate libgcrypt to 1.12.1 (jsc#PED-15059):\n\n* New and extended interfaces:\n - Allow access to the FIPS service indicator via the new\n GCRYCTL_FIPS_SERVICE_INDICATOR control code.\n - Make SHA-1 non-FIPS internally for the 1.12 API\n - Add Dilithium (ML-DSA) support\n - Support optional random-override and support byte string data\n\n* Bug fixes:\n - Use secure MPI in _gcry_mpi_assign_limb_space.\n - Use CSIDL_COMMON_APPDATA instead of /etc on Windows.\n - Apply a Kyber patch from upstream.\n - Fix an edge case in Jent initialization.\n - mceliece6688128f: Fix stack overflow crash on win64/wine\n * Performance:\n - Many performance improvements, new AVX512 implementations for modern CPUs.\n - Add RISC-V Zbb+Zbc implementation of CRC.\n - Add RISC-V vector cryptography implementation of GHASH, AES, SHA256 and SHA512\n - Add AVX2 and AVX512 code paths to improve CRC.\n\nFor a full changelog, see:\nhttps://dev.gnupg.org/source/libgcrypt/history/master/;libgcrypt-1.12.0\n\nUpdate libgpg-error to 1.58:\n\n * New src/gpg-error.c (main): New command \"fconcat\".\n * Rename src/spawn-posix.c (struct gpgrt_spawn_actions): Rename the field to\n ENVP.\n * argparse: Use SYSCONFDIR for /etc.\n * Update translations for Portugese, German\n * src/estream.c (parse_mode): Fix parsing of \"share\". Set sysopen\n flag.\n * syscfg: Add 64-bit Android arch.\n","modified":"2026-04-23T18:26:47.076964Z","published":"2026-04-17T10:34:15Z","related":["CVE-2024-2236"],"upstream":["CVE-2024-2236"],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement//suse-fu-202621232-1/"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-2236"}],"affected":[{"package":{"name":"libgcrypt","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/libgcrypt&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12.1-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libgcrypt20":"1.12.1-160000.1.1","libgpg-error0":"1.58-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-FU-2026:21232-1.json"}},{"package":{"name":"libgpg-error","ecosystem":"SUSE:Linux Micro 6.2","purl":"pkg:rpm/suse/libgpg-error&distro=SUSE%20Linux%20Micro%206.2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.58-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"libgcrypt20":"1.12.1-160000.1.1","libgpg-error0":"1.58-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-FU-2026:21232-1.json"}}],"schema_version":"1.7.5"}