stable

perl-Crypt-PBKDF2-0.261630-1.fc44

FEDORA-2026-5b12cc327e created by pghmcfc 3 months ago for Fedora 44

This update addresses a number of security issues:

  • Change the default hash algorithm to HMAC-SHA256, and increase the default number of iterations to 600,000, in line with current OWASP recommendations (CVE-2026-9641)
  • Generate salts using Crypt::URandom (a strong system RNG) instead of perl's builtin rand(), which is not cryptographically secure (CVE-2026-9638)
  • Use a constant-time comparison in validate to avoid timing attacks (CVE-2017-20240)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-5b12cc327e

This update has been submitted for testing by pghmcfc.

3 months ago

This update's test gating status has been changed to 'ignored'.

3 months ago

This update has been pushed to testing.

3 months ago

pghmcfc edited this update.

3 months ago

This update has been submitted for stable by bodhi.

3 months ago

This update has been pushed to stable.

3 months ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-1
Stable by Karma
2
Stable by Time
7 days
Dates
submitted
3 months ago
in testing
3 months ago
in stable
3 months ago
modified
3 months ago
approved
3 months ago
BZ#2488228 perl-Crypt-PBKDF2-0.261630 is available
0
0
BZ#2488894 CVE-2017-20240 perl-Crypt-PBKDF2: information disclosure via timing attack [fedora-all]
0
0
BZ#2488896 CVE-2026-9641 perl-Crypt-PBKDF2: weak default algorithm and insufficient iterations [fedora-all]
0
0
BZ#2488899 CVE-2026-9638 perl-Crypt-PBKDF2: generation of insecure random values for salts [fedora-all]
0
0

Automated Test Results