Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 42: FEDORA-2025-34b9058968 important: perl-CryptX integer overflow

fedora
Calendar Grey June 27, 2025
Dist Fedora Esm H88
Fedora 42's Perl-CryptX has received an important update to fix a serious buffer overflow vulnerability. Immediate application of this patch is advised.
Update to 0.087, fixes CVE-2025-40914

Summary

This Perl library provides a cryptography based on LibTomCrypt library.

Update Information:

Update to 0.087, fixes CVE-2025-40914

Change Log

* Thu Jun 12 2025 Xavier Bachelot - 0.087-2 - Use any version of Math::BigInt and Math::BigFloat - Fix bundled Provides: * Wed Jun 11 2025 Xavier Bachelot - 0.087-1 - Update to 0.087 (RHBZ#2372355,RHBZ#2372356,RHBZ#2372357,RHBZ#2372358) - Fix CVE-2025-40914 * Sat May 3 2025 Xavier Bachelot - 0.086-1 - Update to 0.086 (RHBZ#2363852, RHBZ#2354493) * Tue Feb 11 2025 Xavier Bachelot - 0.085-1 - Update to 0.085 (RHBZ#2344451)

References


[ 1 ] Bug #2372355 - CVE-2025-40914 perl-CryptX: Perl CryptX code execution via integer overflow [epel-8] https://bugzilla.redhat.com/show_bug.cgi?id=2372355 [ 2 ] Bug #2372356 - CVE-2025-40914 perl-CryptX: Perl CryptX code execution via integer overflow [epel-9] https://bugzilla.redhat.com/show_bug.cgi?id=2372356 [ 3 ] Bug #2372357 - CVE-2025-40914 perl-CryptX: Perl CryptX code execution via integer overflow [fedora-41] https://bugzilla.redhat.com/show_bug.cgi?id=2372357 [ 4 ] Bug #2372358 - CVE-2025-40914 perl-CryptX: Perl CryptX code execution via integer overflow [fedora-42] https://bugzilla.redhat.com/show_bug.cgi?id=2372358

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2025-34b9058968' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: perl-CryptX
Product: Fedora 42
Version: 0.087
Release: 2.fc42
Summary: Cryptographic toolkit

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here