Critical Info Disclosure Vulnerability in phpseclib for Fedora 42 and 43

Critical Info Disclosure Vulnerability in phpseclib for Fedora 42 and 43

First seen 30 Mar 2026, 07:30 UTC Linuxsecurity 72.8

Article Content

Browse articles
ThreatCluster

A critical information disclosure vulnerability (CVE-2026-32935) was identified in the phpseclib library, affecting Fedora 42 and 43. The vulnerability allows attackers to exploit a padding oracle timing attack when using AES in CBC mode, potentially disclosing sensitive information. The issue was published on 2026-03-20 and has been addressed in updates for both Fedora versions. Fedora 43 has been updated to version 3.0.50, while Fedora 42 has been updated to version 2.0.52 to mitigate the risk. Users are advised to apply the updates immediately to protect against potential exploitation. The updates can be installed using the 'dnf' package manager. The vulnerability impacts systems utilizing the affected versions of phpseclib, which is widely used for cryptographic operations in PHP applications. Failure to update may leave systems vulnerable to attacks that exploit this flaw.

Key Points: • CVE-2026-32935 allows information disclosure via padding oracle timing attacks. • Affected systems include Fedora 42 and 43 using phpseclib library. • Updates to phpseclib versions 2.0.52 and 3.0.50 are available to mitigate the risk.

Timeline

2026-03-19
Fedora 42 updated to phpseclib 2.0.52
2026-03-20
CVE-2026-32935 published
2026-03-21
Fedora 43 updated to phpseclib 3.0.50
2026-03-30
Current reporting on the vulnerability and updates