On Sun, Apr 19, 2026 at 08:45:20AM +0200, Alejandro Colomar via Mutt-dev wrote:
On 2026-04-19T13:48:35+0800, Kevin J. McCarthy wrote:Inside show_one_sig_status(), if the error code is GPG_ERR_NO_PUBKEY, key is NULL. However, show_sig_summary() doesn't check for a NULL key before dereferencing for the "key expired" case.Thanks to [email protected] for the security report. Thanks to Alejandro Colomar for his review and suggestion to keep the ternary operator.Reviewed-by: Alejandro Colomar <[email protected]>
Pushed to stable and merged to master. -- Kevin J. McCarthy GPG Fingerprint: 8975 A9B3 3AA3 7910 385C 5308 ADEF 7684 8031 6BDA
signature.asc
Description: PGP signature
