Cipher Preferences Ignored for Kyber keys?

scuffbox scuffbox at proton.me
Sun Jul 26 01:07:47 CEST 2026


Hello,

I hope this is the appropriate place to mention this. I do not normally post to mailing lists, but cannot register for the bug tracker.

On upgrading to 2.5.x (2.5.20 and 2.5.21) recently to test Kyber keys, I have noticed that any preferences relating to cipher choice are being ignored.

AES256 appears to be used for encryption to Kyber subkeys regardless of the contents of the public key's cipher preferences and the local config's personal-cipher-preferences. Both could have a first option of any other cipher, and it would not be used. AES256 can even be removed entirely from both and still be chosen.

Using `--disable-cipher AES256` results in:

    gpg: Ohhhh jeeee: there is a bug at seskey.c:50:make_session_key

Am I missing something about Kyber keys?  I can manually choose any other cipher for the encryption using `--cipher`, so I'm thinking this is a bug when selecting the cipher for encrypting to Kyber keys specifically. Encrypting to a non-Kyber subkey results in the preferences being honored as expected.

--
Scuff



More information about the Gnupg-users mailing list