On Sun, Apr 19, 2026 at 08:45:20AM +0200, Alejandro Colomar via Mutt-dev wrote:
On 2026-04-19T13:48:35+0800, Kevin J. McCarthy wrote:
Inside show_one_sig_status(), if the error code is GPG_ERR_NO_PUBKEY,
key is NULL.  However, show_sig_summary() doesn't check for a NULL key
before dereferencing for the "key expired" case.

Thanks to [email protected] for the security report.

Thanks to Alejandro Colomar for his review and suggestion to keep the
ternary operator.

Reviewed-by: Alejandro Colomar <[email protected]>

Pushed to stable and merged to master.

--
Kevin J. McCarthy
GPG Fingerprint: 8975 A9B3 3AA3 7910 385C  5308 ADEF 7684 8031 6BDA

Attachment: signature.asc
Description: PGP signature

Reply via email to