This Module is intended to provide an interface to the strongest available
source of non-blocking randomness on the current platform.
Update Information:
This release fixes CVE-2026-2474 (a heap buffer overflow) and handling failed read syscalls.
* Mon Feb 23 2026 Petr Pisar
[ 1 ] Bug #2440306 - CVE-2026-2474 crypt-urandom: Crypt::URandom for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom()
https://bugzilla.redhat.com/show_bug.cgi?id=2440306
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-eb6b1039eb' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label
Get the latest Linux and open source security news straight to your inbox.