Oracular is also affected, I can reproduce on an up-to-date debootstrap'ed oracular chroot. Here is a debdiff for oracular applicable to 2.4.4-2ubuntu18.2. I built this in an up-to-date debootstrap'ed oracular chroot. Patched package exhibits the expected/correct behaviour when playing steps to reproduce the issue.
** Patch added: "Patch for oracular applying the upstream commit fixing the issue" https://bugs.launchpad.net/ubuntu/+source/gnupg2/+bug/2114775/+attachment/5886365/+files/oracular-1-2.4.4-2ubuntu18.3.debdiff -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2114775 Title: Key validity not computed when key is certified by a trusted "certify- only" key (regression due to patch for CVE-2025-30258) To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/gnupg2/+bug/2114775/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
