Back Linuxsecurity Fedora 42 perl-Crypt-URandom Key Memory Overflow Resolution 2026
This Module is intended to provide an interface to the strongest available source of non-blocking randomness on the current platform. Update Information : This release fixes CVE-2026-2474 (a heap buffer overflow) and handling failed read syscalls.
This Module is intended to provide an interface to the strongest available
source of non-blocking randomness on the current platform.
This release fixes CVE-2026-2474 (a heap buffer overflow) and handling failed read syscalls.
* Mon Feb 23 2026 Petr Pisar - 0.55-1 - 0.55 bump (CVE-2026-2474, bug #2440312)
* Mon Feb 23 2026 Petr Pisar - 0.55-1 - 0.55 bump (CVE-2026-2474, bug #2440312)
[ 1 ] Bug #2440306 - CVE-2026-2474 crypt-urandom: Crypt::URandom for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom()
[ 1 ] Bug #2440306 - CVE-2026-2474 crypt-urandom: Crypt::URandom for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom()
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b0bf6e9c9b' at the command line. For more information, refer to the dnf documentation available at
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b0bf6e9c9b' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
