stable

perl-Crypt-PBKDF2-0.261630-1.fc43

FEDORA-2026-e8231b773d created by pghmcfc a month ago for Fedora 43

This update addresses a number of security issues:

  • Change the default hash algorithm to HMAC-SHA256, and increase the default number of iterations to 600,000, in line with current OWASP recommendations (CVE-2026-9641)
  • Generate salts using Crypt::URandom (a strong system RNG) instead of perl's builtin rand(), which is not cryptographically secure (CVE-2026-9638)
  • Use a constant-time comparison in validate to avoid timing attacks (CVE-2017-20240)

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2026-e8231b773d

This update has been submitted for testing by pghmcfc.

a month ago

This update's test gating status has been changed to 'ignored'.

a month ago

This update has been pushed to testing.

a month ago

pghmcfc edited this update.

4 weeks ago

This update has been submitted for stable by bodhi.

3 weeks ago

This update has been pushed to stable.

3 weeks ago

Please log in to add feedback.

Metadata
Type
security
Severity
medium
Karma
0
Signed
Content Type
RPM
Test Gating
Autopush Settings
Unstable by Karma
-1
Stable by Karma
2
Stable by Time
7 days
Dates
submitted
a month ago
in testing
a month ago
in stable
3 weeks ago
modified
4 weeks ago
approved
3 weeks ago
BZ#2488228 perl-Crypt-PBKDF2-0.261630 is available
0
0
BZ#2488894 CVE-2017-20240 perl-Crypt-PBKDF2: information disclosure via timing attack [fedora-all]
0
0
BZ#2488896 CVE-2026-9641 perl-Crypt-PBKDF2: weak default algorithm and insufficient iterations [fedora-all]
0
0
BZ#2488899 CVE-2026-9638 perl-Crypt-PBKDF2: generation of insecure random values for salts [fedora-all]
0
0

Automated Test Results