Ubuntu 26.04 LTS Salt Weakness in Crypt-SaltedHash Exposes Systems to Attacks

Ubuntu 26.04 LTS Salt Weakness in Crypt-SaltedHash Exposes Systems to Attacks

First seen 11 Jun 2026, 08:15 UTC UbuntuLinuxsecurity 82% similarity 57.8

Article Content

Browse articles
ThreatCluster

A significant vulnerability has been identified in the Crypt-SaltedHash module across multiple Ubuntu releases, including 26.04 LTS and earlier versions. The flaw arises from the use of a weak pseudo-random number generator, which allows attackers to predict generated salts. This predictability can lead to a compromise of cryptographic protections, making systems vulnerable to unauthorized access. Affected versions include Ubuntu 26.04 LTS, 25.10, 24.04 LTS, 22.04 LTS, 20.04 LTS, 18.04 LTS, and 16.04 LTS. Users are advised to update to the latest package versions to mitigate the risk. The issue was disclosed in Ubuntu Security Notice USN-8418-1. A standard system update will resolve the vulnerability. The flaw emphasizes the importance of using strong cryptographic practices.

Key Points: • Crypt-SaltedHash in multiple Ubuntu versions has a salt generation flaw. • Attackers can predict salts, compromising cryptographic security. • Users must update to the latest package versions to mitigate risks.

ThreatCluster AI

Timeline

2026-06-10
Vulnerability disclosed in USN-8418-1
Ubuntu announced a security issue with Crypt-SaltedHash affecting multiple versions, urging users to update.
Ubuntu
2026-06-11
Linuxsecurity reports on the vulnerability
Linuxsecurity published details on the Crypt-SaltedHash flaw, reiterating the need for updates across affected Ubuntu versions.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story