Skip to content
Fedora 43 perl-Crypt-DSA Important Key Reuse Vulnerability CVE-2026

Fedora 43 perl-Crypt-DSA Important Key Reuse Vulnerability CVE-2026

Linuxsecurity LinuxSecurity Advisories June 24, 2026

This update, to the current upstream release, prevents key material reuse for multiple signing events (CVE-2026-12205, CWE-323).

* Mon Jun 15 2026 Paul Howarth - 1.21-1 - Update to 1.21 - Fixed key material reuse for multiple signing events (CVE-2026-12205, CWE-323) - sign() reused the DSA nonce k across signatures (r and k^-1 were cached on the key and not regenerated), allowing private-key recovery from two signatures over different messages - Now generates a fresh nonce per signature - Keys used to sign more than once with an affected version should be considered compromised * Fri Jun 12 2026 Yaakov Selkowitz - 1.20-2 - Rebuilt for openssl 4.0

* Mon Jun 15 2026 Paul Howarth - 1.21-1 - Update to 1.21 - Fixed key material reuse for multiple signing events (CVE-2026-12205, CWE-323) - sign() reused the DSA nonce k across signatures (r and k^-1 were cached on the key and not regenerated), allowing private-key recovery from two signatures over different messages - Now generates a fresh nonce per signature - Keys used to sign more than once with an affected version should be considered compromised * Fri Jun 12 2026 Yaakov Selkowitz - 1.20-2 - Rebuilt for openssl 4.0

[ 1 ] Bug #2491340 - CVE-2026-12205 perl-Crypt-DSA: Crypt::DSA: Private-key recovery via nonce reuse across signatures [fedora-all]

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-5cf57e43e3' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Companies (1)

Tools (1)