{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/centos-stream8els/vex/2026/cve-2026-57062-els_os-centos-stream8els.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-07-28T17:54:27Z",
      "generator": {
        "date": "2026-07-28T17:54:26Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CVE-2026-57062-ELS_OS-CENTOS-STREAM8ELS",
      "initial_release_date": "2026-06-23T18:18:00Z",
      "revision_history": [
        {
          "date": "2026-06-23T18:18:00Z",
          "number": "1",
          "summary": "Initial version"
        },
        {
          "date": "2026-07-28T01:29:16Z",
          "number": "2",
          "summary": "Official Publication"
        },
        {
          "date": "2026-07-28T17:54:27Z",
          "number": "3",
          "summary": "Update document"
        }
      ],
      "status": "final",
      "version": "3"
    },
    "title": "Security update on CVE-2026-57062"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Community Enterprise Operating System 8",
                "product": {
                  "name": "Community Enterprise Operating System 8",
                  "product_id": "CentOS-Stream-8",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:centos:centos:8:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Community Enterprise Operating System"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "gnupg2-smime-0:2.2.20-3.el8.x86_64",
                "product": {
                  "name": "gnupg2-smime-0:2.2.20-3.el8.x86_64",
                  "product_id": "gnupg2-smime-0:2.2.20-3.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/gnupg2-smime@2.2.20-3.el8?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnupg2-0:2.2.20-3.el8.x86_64",
                "product": {
                  "name": "gnupg2-0:2.2.20-3.el8.x86_64",
                  "product_id": "gnupg2-0:2.2.20-3.el8.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/centos/gnupg2@2.2.20-3.el8?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "Red Hat, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "gnupg2-smime-0:2.2.20-3.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnupg2-smime-0:2.2.20-3.el8.tuxcare.els1.x86_64",
                  "product_id": "gnupg2-smime-0:2.2.20-3.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/gnupg2-smime@2.2.20-3.el8.tuxcare.els1?arch=x86_64"
                  }
                }
              },
              {
                "category": "product_version",
                "name": "gnupg2-0:2.2.20-3.el8.tuxcare.els1.x86_64",
                "product": {
                  "name": "gnupg2-0:2.2.20-3.el8.tuxcare.els1.x86_64",
                  "product_id": "gnupg2-0:2.2.20-3.el8.tuxcare.els1.x86_64",
                  "product_identification_helper": {
                    "purl": "pkg:rpm/tuxcare/gnupg2@2.2.20-3.el8.tuxcare.els1?arch=x86_64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "x86_64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnupg2-smime-0:2.2.20-3.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:gnupg2-smime-0:2.2.20-3.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "gnupg2-smime-0:2.2.20-3.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnupg2-0:2.2.20-3.el8.tuxcare.els1.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:gnupg2-0:2.2.20-3.el8.tuxcare.els1.x86_64"
        },
        "product_reference": "gnupg2-0:2.2.20-3.el8.tuxcare.els1.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnupg2-smime-0:2.2.20-3.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:gnupg2-smime-0:2.2.20-3.el8.x86_64"
        },
        "product_reference": "gnupg2-smime-0:2.2.20-3.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "gnupg2-0:2.2.20-3.el8.x86_64 as a component of Community Enterprise Operating System 8",
          "product_id": "CentOS-Stream-8:gnupg2-0:2.2.20-3.el8.x86_64"
        },
        "product_reference": "gnupg2-0:2.2.20-3.el8.x86_64",
        "relates_to_product_reference": "CentOS-Stream-8"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2026-57062",
      "notes": [
        {
          "category": "description",
          "text": "CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "CentOS-Stream-8:gnupg2-0:2.2.20-3.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:gnupg2-0:2.2.20-3.el8.x86_64",
          "CentOS-Stream-8:gnupg2-smime-0:2.2.20-3.el8.tuxcare.els1.x86_64",
          "CentOS-Stream-8:gnupg2-smime-0:2.2.20-3.el8.x86_64"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2026-57062"
        }
      ],
      "release_date": "2026-06-23T18:18:00Z",
      "remediations": [
        {
          "category": "no_fix_planned",
          "date": "2026-07-28T17:40:07.815429Z",
          "details": "This issue only affects CMS/S/MIME decryption paths that process attacker-supplied AES‑GCM content with gpgsm; gpgsm is a non-networked command-line component and is not exposed as a service by default, so exploitation generally requires a delivery path that causes the host to parse untrusted CMS data. The flaw reduces the authentication tag length accepted during decryption (4 bytes instead of the required minimum 12), impacting only the integrity/confidentiality of the specific CMS payload without enabling code execution, privilege escalation, or system compromise. In typical server/VM deployments that do not automatically handle S/MIME via gpgsm, the practical risk is low and this CVE can be safely deprioritized.",
          "product_ids": [
            "CentOS-Stream-8:gnupg2-0:2.2.20-3.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:gnupg2-0:2.2.20-3.el8.x86_64",
            "CentOS-Stream-8:gnupg2-smime-0:2.2.20-3.el8.tuxcare.els1.x86_64",
            "CentOS-Stream-8:gnupg2-smime-0:2.2.20-3.el8.x86_64"
          ]
        }
      ]
    }
  ]
}