Critical Timing Attack Fix for Fedora's perl-Net-OAuth

Critical Timing Attack Fix for Fedora's perl-Net-OAuth

First seen 8 Sep 2026, 12:03 UTC Linuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Fedora has released important updates for the perl-Net-OAuth package to address a critical timing attack vulnerability. Versions prior to 0.33 are affected, allowing attackers to exploit non-constant-time comparisons in signature verification, leading to potential information disclosure. The vulnerability is identified as CVE-2026-75589, published on August 19, 2026. The update, which fixes this issue, was made available on August 27, 2026. Users are advised to upgrade to version 0.33 to mitigate the risk. The flaw impacts all Fedora systems using the affected versions of the Net::OAuth module. The updates can be installed via the 'dnf' package manager. Security professionals should prioritize patching to prevent potential exploitation.

Key Points: • Fedora's perl-Net-OAuth versions before 0.33 are vulnerable to a timing attack. • CVE-2026-75589 was published on August 19, 2026, and fixed in an update on August 27, 2026. • Users must upgrade to version 0.33 to mitigate the risk of information disclosure.

Ask AI about this cluster

Timeline

2026-08-19
CVE-2026-75589 published
CVE-2026-75589 details a timing attack vulnerability in perl-Net-OAuth affecting versions before 0.33.
Linuxsecurity
2026-08-19
CVE-2026-72889 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-27
Update released for perl-Net-OAuth
Fedora released version 0.33 to fix the timing attack vulnerability identified as CVE-2026-75589.
Linuxsecurity