Linuxsecurity
Critical Timing Attack Fix for Fedora's perl-Net-OAuth
Article Content
Fedora has released important updates for the perl-Net-OAuth package to address a critical timing attack vulnerability. Versions prior to 0.33 are affected, allowing attackers to exploit non-constant-time comparisons in signature verification, leading to potential information disclosure. The vulnerability is identified as CVE-2026-75589, published on August 19, 2026. The update, which fixes this issue, was made available on August 27, 2026. Users are advised to upgrade to version 0.33 to mitigate the risk. The flaw impacts all Fedora systems using the affected versions of the Net::OAuth module. The updates can be installed via the 'dnf' package manager. Security professionals should prioritize patching to prevent potential exploitation.
Key Points: • Fedora's perl-Net-OAuth versions before 0.33 are vulnerable to a timing attack. • CVE-2026-75589 was published on August 19, 2026, and fixed in an update on August 27, 2026. • Users must upgrade to version 0.33 to mitigate the risk of information disclosure.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.