GnuPG VS-Desktop 3.3.7

GnuPG VS-Desktop® version 3.3.7.0 has been available since 2026-04-20. It fixes a security issue. Version 3.3.7.1 has been available since 2026-06-25 which additionally installs the PCA-1-Verwaltung-26 root certificate. The previous version was 3.3.6.

Notes to Admins

We recommend updating to this version because an easy to mount DoS (denial-of-service) attack was possible. This release fixes the problem. (T8211)

Solved Bugs

Engine (GnuPG)

  • libgcrypt: Fix possible ECDH buffer overwrite with zeroes. (T8211)
  • gpgsm: Add a certificate chain check for de-vs compliance (T8188)
  • gpgsm: Allow to show rsaPSS certificates as VS-NfD compliant in listings. (T8222)
  • agent: Accept a trustlist with a missing LF at the end. (T8078)

GUI (Kleopatra)

  • Fix issue with hanging encryption when S/MIME validity check fails. (T8187)

Known Issues

S/MIME Decryption

Decrypting S/MIME encrypted mails and text files fails if the certificate used has expired. The error messages for GpgOL and for file decryption in Kleopatra are, resp:

S/MIME Encrypted message (decryption not possible)
Could not decrypt the data: Invalid crypto engine

Decryption failed: Invalid crypto engine.

Workaround

Files can be decrypted on the command line instead. For GpgOL there is no workaround suited for production systems.

Versions of the Components

Component Version Remarks
GnuPG 2.2.54 T8170
Kleopatra 3.3.7  
GpgOL 2.7.2  
GpgEX 1.0.11  
Libgcrypt 1.8.13 T8224
Libksba 1.6.8 T7174

This page as PDF.