Back Linuxsecurity Fedora 43 perl-Crypt-SysRandom-XS Important Heap Overflow CVE-2026
This module uses whatever C interface is available to procure cryptographically random data from the system. Update Information : 0.011 - Update data pointer on resize for rdrand; Clean up string length handling 0.010 - Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS
This module uses whatever C interface is available to procure
cryptographically random data from the system.
0.011 - Update data pointer on resize for rdrand; Clean up string length handling 0.010 - Disallow requesting strings with negative lengths CVE-2026-2597; Try arc4random in stdlib.h first; Correct value of PROTOTYPES keyword in XS
* Mon Mar 2 2026 Jitka Plesnikova - 0.011-1 - 0.011 bump (rhbz#2440318)
* Mon Mar 2 2026 Jitka Plesnikova - 0.011-1 - 0.011 bump (rhbz#2440318)
[ 1 ] Bug #2443384 - CVE-2026-2597 perl-Crypt-SysRandom-XS: heap-based buffer overflow in the XS function random_bytes() [fedora-all]
[ 1 ] Bug #2443384 - CVE-2026-2597 perl-Crypt-SysRandom-XS: heap-based buffer overflow in the XS function random_bytes() [fedora-all]
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7b9874a01f' at the command line. For more information, refer to the dnf documentation available at
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-7b9874a01f' at the command line. For more information, refer to the dnf documentation available at
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
