GnuPG VS-Desktop 3.3.7
GnuPG VS-Desktop® version 3.3.7.0 has been available since 2026-04-20. It fixes a security issue. Version 3.3.7.1 has been available since 2026-06-25 which additionally installs the PCA-1-Verwaltung-26 root certificate. The previous version was 3.3.6.
Notes to Admins
We recommend updating to this version because an easy to mount DoS (denial-of-service) attack was possible. This release fixes the problem. (T8211)
Solved Bugs
Engine (GnuPG)
libgcrypt: Fix possible ECDH buffer overwrite with zeroes. (T8211)gpgsm: Add a certificate chain check for de-vs compliance (T8188)gpgsm: Allow to show rsaPSS certificates as VS-NfD compliant in listings. (T8222)agent: Accept atrustlistwith a missing LF at the end. (T8078)
GUI (Kleopatra)
- Fix issue with hanging encryption when S/MIME validity check fails. (T8187)
Known Issues
S/MIME Decryption
Decrypting S/MIME encrypted mails and text files fails if the certificate used has expired. The error messages for GpgOL and for file decryption in Kleopatra are, resp:
S/MIME Encrypted message (decryption not possible)
Could not decrypt the data: Invalid crypto engine
Decryption failed: Invalid crypto engine.
Workaround
Files can be decrypted on the command line instead. For GpgOL there is no workaround suited for production systems.
Versions of the Components
| Component | Version | Remarks |
|---|---|---|
| GnuPG | 2.2.54 | T8170 |
| Kleopatra | 3.3.7 | |
| GpgOL | 2.7.2 | |
| GpgEX | 1.0.11 | |
| Libgcrypt | 1.8.13 | T8224 |
| Libksba | 1.6.8 | T7174 |
This page as PDF.