Fedora perl-Crypt-URandom Heap Buffer Overflow Fix Released

Fedora perl-Crypt-URandom Heap Buffer Overflow Fix Released

First seen 4 Mar 2026, 10:08 UTC Linuxsecurity 18.3

Article Content

Browse articles
ThreatCluster

Fedora has released updates for the perl-Crypt-URandom module to address a heap buffer overflow vulnerability identified as CVE-2026-2474. This vulnerability affects the module's ability to handle failed read syscalls, potentially compromising the randomness source on the platform. The updates were made available on February 23, 2026, by Petr Pisar.

Timeline

2026-02-16
CVE-2026-2474 published
2026-02-23
Patch released for perl-Crypt-URandom by Petr Pisar
2026-03-04
Articles published about the vulnerability and fix