Skip to content
Fedora 42 php-phpseclib Information Disclosure AES 2026

Fedora 42 php-phpseclib Information Disclosure AES 2026

Linuxsecurity •LinuxSecurity Advisories • March 28, 2026

MIT-licensed pure-PHP implementations of an arbitrary-precision integer arithmetic library, fully PKCS#1 (v2.1) compliant RSA, DES, 3DES, RC4, Rijndael, AES, Blowfish, Twofish, SSH-1, SSH-2, SFTP, and X.509 Update Information : Update to v2.0.52

MIT-licensed pure-PHP implementations of an arbitrary-precision integer

arithmetic library, fully PKCS#1 (v2.1) compliant RSA, DES, 3DES, RC4,

Rijndael, AES, Blowfish, Twofish, SSH-1, SSH-2, SFTP, and X.509

* Thu Mar 19 2026 Artur Frenszek-Iwicki - 2.0.52-1 - Update to v2.0.52

* Thu Mar 19 2026 Artur Frenszek-Iwicki - 2.0.52-1 - Update to v2.0.52

[ 1 ] Bug #2449633 - CVE-2026-32935 php-phpseclib: phpseclib: Information disclosure via padding oracle timing attack when using AES in CBC mode [fedora-42]

[ 1 ] Bug #2449633 - CVE-2026-32935 php-phpseclib: phpseclib: Information disclosure via padding oracle timing attack when using AES in CBC mode [fedora-42]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bfeb46516b' at the command line. For more information, refer to the dnf documentation available at

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bfeb46516b' at the command line. For more information, refer to the dnf documentation available at

Extracted Entities

Attack Types (1)

Vulnerabilities (1)