In GnuPG before 2.5.17, a stack-based buffer overflow exists in tpm2daemon during handling of the PKDECRYPT command for TPM-backed RSA and ECC keys.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-24882.json"