🛡️ SUSE-FU-2026:21232-1 — libgcrypt
Description
Feature update for libgcrypt, libgpg-error
This update for libgcrypt, libgpg-error fixes the following issues:
Update libgcrypt to 1.12.1 (jsc#PED-15059):
- New and extended interfaces:
- Allow access to the FIPS service indicator via the new
GCRYCTL_FIPS_SERVICE_INDICATOR control code.
- Make SHA-1 non-FIPS internally for the 1.12 API
- Add Dilithium (ML-DSA) support
- Support optional random-override and support byte string data
- Bug fixes:
- Use secure MPI in _gcry_mpi_assign_limb_space.
- Use CSIDL_COMMON_APPDATA instead of /etc on Windows.
- Apply a Kyber patch from upstream.
- Fix an edge case in Jent initialization.
- mceliece6688128f: Fix stack overflow crash on win64/wine
- Performance:
- Many performance improvements, new AVX512 implementations for modern CPUs.
- Add RISC-V Zbb+Zbc implementation of CRC.
- Add RISC-V vector cryptography implementation of GHASH, AES, SHA256 and SHA512
- Add AVX2 and AVX512 code paths to improve CRC.
For a full changelog, see:
https://dev.gnupg.org/source/libgcrypt/history/master/;libgcrypt-1.12.0
Update libgpg-error to 1.58:
- New src/gpg-error.c (main): New command "fconcat".
- Rename src/spawn-posix.c (struct gpgrt_spawn_actions): Rename the field to
ENVP.
- argparse: Use SYSCONFDIR for /etc.
- Update translations for Portugese, German
- src/estream.c (parse_mode): Fix parsing of "share". Set sysopen
flag.
- syscfg: Add 64-bit Android arch.
Affected software
SUSE-FU-2026:21232-1 is recorded against 2 packages.
- libgcrypt (fixed in 1.12.1-160000.1.1)
- libgpg-error (fixed in 1.58-160000.1.1)
Timeline and source
Published on 17 April 2026 and last revised on 23 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| libgcrypt | — | 1.12.1-160000.1.1 |
| libgpg-error | — | 1.58-160000.1.1 |
References
Similar Threats
- Unknown ALSA-2026:50144
- Unknown ALSA-2026:50147
- Unknown ALSA-2026:47117
- Unknown MGASA-2026-0212
- Unknown BELL-CVE-2026-41989
More SUSE FU 2026 advisories
Browse all of SUSE FU 2026 in the advisory index.
Free Vulnerability Check
Is your site affected by SUSE-FU-2026:21232-1?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-FU-2026:21232-1 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.