Release GnuPG 2.5.22
Open, NormalPublic

Assigned To
None
Authored By
werner
Jul 2 2026, 3:16 PM
Subscribers

Description

Noteworthy changes in version 2.5.22 (2026-08-31)

  • New and extended features:
    • gpg: New option "primary" for the --card-edit "generate" command. This option is useful to create only the primary key on the first slot of an OpenPGP card. [T8344]
    • Make detection of the installation directory work for macOS. [rG0be940905d]
    • gpgsm: Emit issuer and serial no. when the certificate is not found. [T8363]
  • Bug fixes:
    • gpg: Fix trustdb recursive lock problem. [T8317]
    • gpg: Fix using wrong fingerprint length for the intended recipient fingerprint. [T8330]
    • gpg: Fix wrong assertion edge case in building packets. [rGe319d82d7e]
    • gpg: Fix possible double free in import_revoke_cert. [T8328]
    • gpg: Fix long standing regression of "bkuptocard". [T8344,rGf103eaee63]
    • gpg: Fix TOFU trust models to actually check UTK signatures. [T8404]
    • gpg: Don't enable the partial file guard if already done. Fix regression introduced by partial file guards. [T8399]
    • gpgsm: Only display de-vs compliance status in de-vs compliance mode. [T8333]
    • gpgsm: Return 0 if decryption of multi recipient file succeeds. [T8340]
    • gpgsm: Check args for special file names and dashes. [T8347]
    • gpgsm: Fix keydb_get_flags with keyboxd. [T8048]
    • g13: Add sanity check on the syntax of the dmsetup algo string. [rG386c3e63b1]
  • Other changes:
    • gpg,gpgsm: Emit signing time as status output also for bad signatures. [T8364]
    • gpg: Emit status line for failed write. [T8398]
    • scd: Put a workaround for buggy CCID device. [T8331]
    • scd: Allow switching APP when --pcsc-shared is enabled. [rGf783c02525]
    • gpgconf: Print a warning on Windows on insufficent global config directory permissions. [rG56eb3148c7]

(prev: T8262 next: T8425)

Related Objects

Mentioned In
T8425: Release GnupG 2.5.23
T8262: Release GnuPG 2.5.21
Mentioned Here
T8425: Release GnupG 2.5.23
rGe319d82d7e3a: gpg: Fix assertion.
rGf103eaee63f7: gpg: Fix long standing regression of "bkuptocard"
rG0be940905d70: common: Make unix_rootdir work for macOS.
rGf783c02525c3: scd: Allow switching APP when opt.pcsc_shared is enabled.
rG386c3e63b1ca: g13: Add sanity check on the syntax of the dmsetup algo string.
rG56eb3148c7b8: gpgconf: Print a warning on Windows on insufficent /etc permissions.
T8048: Keyboxd: S/MIME certificate is imported on ldap search
T8317: Recursive trustdb lock problem
T8328: double keydb_release() in error handling path of g10/import.c : import_revoke_cert
T8331: scd: Support Nitrokey 3
T8333: Kleopatra: S/MIME decryption fails for certs with crl check problems
T8340: GpgSM: Decryption with multiple recipients emits a failure, if the first pinenty is cancelled
T8344: gpg: Fix edit-key bkuptocard
T8347: GpgSM: Verification of detached signature via pipe fails
T8363: gpgsm should print issuer and serial no. of unknown signing certificates as status information
T8364: gpg does not emit creation time of bad signatures
T8398: Kleopatra: No error is given when decrypted file can not be saved due to full disk
T8399: No file saved on decryption if signing certificate is not available
T8404: gpg's TOFU trust model allows authentication bypass
rG245330ebeaf6: scd:openpgp: Fix CHV1 retry counter byte index.
rGab9ce5f5e775: w32:common: Fix usleep in w32_wait_when_sharing_violation.
rG4c7e68cf3d33: gpgsm: Require a minimum tag length for GCM decryption.
rGca25a7a61beb: scd: Fix condition to retrieve ATR.
T7873: Decrypt to foo.gpg.part files and rename
T8029: IPC error on batch import of secret kyber cert
T8188: gpgsm: No error/warning on verification or decryption in case of trusted but not VS-compliant certificate
T8252: Use RECP_FPR subpacket for standalone designated revocations.
T8261: GnuPG: Assert in gpgconf fails on change of keyserver option, if value includes a comma
T8277: Potential use-after-free in keygen when handling keyserver option
T8281: scd: Have a limit for data object handling
T8303: Heap OOB reads in dirmngr DNS CERT/DANE parsing
T8262: Release GnuPG 2.5.21

Event Timeline

werner triaged this task as Normal priority.Jul 2 2026, 3:16 PM
werner created this task.
werner created this object with edit policy "Administrators".
werner updated the task description. (Show Details)
werner renamed this task from Release GnuPG 2.5.22 to Release GnuPG 2.5.23.Jul 2 2026, 3:47 PM
werner renamed this task from Release GnuPG 2.5.23 to Release GnuPG 2.5.22.Jul 2 2026, 3:49 PM
werner updated the task description. (Show Details)