Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) .. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-fcfc08d46c 2026-07-12 01:10:38.798612+00:00 -------------------------------------------------------------------------------- Name : perl-Crypt-DSA Product : Fedora 44 Version : 1.22 Release : 1.fc44 URL : https://metacpan.org/release/Crypt-DSA Summary : Perl module for DSA signatures and key generation Description : Crypt::DSA is an implementation of the DSA (Digital Signature Algorithm) signature verification system. This package provides DSA signing, signature verification, and key generation. DSA (Digital Signature Algorithm) signatures are no longer considered to be adequate for security. This module should only be used for verifying old signatures and should not be used for new signatures. That being said, some technologies still require DSA signatures even now. Consider using other solutions or explicitly not using DSA signatures. Crypt-DSA-GMP is a possible replacement. -------------------------------------------------------------------------------- Update Information: This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) . -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Paul Howarth - 1.22-1 - Update to 1.22 - Hardening: Use a fresh, independent CSPRNG witness every round - Security fix: Modulo bias in key generation (CVE-2026-14570); an attack with hundreds of signatures could lead to full private-key compromise; keys should be considered compromised and new keys should be generated * Fri Jun 19 2026 Yaakov Selkowitz - 1.21-2 - Rebuilt for OpenSSL4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497529 - CVE-2026-14570 perl-Crypt-DSA: Crypt::DSA: Private key recovery due to biased random number generation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497529 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-fcfc08d46c' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) .. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-b77b9c5f04 2026-07-12 00:58:35.903674+00:00 -------------------------------------------------------------------------------- Name : perl-Crypt-DSA Product : Fedora 43 Version : 1.22 Release : 1.fc43 URL : https://metacpan.org/release/Crypt-DSA Summary : Perl module for DSA signatures and key generation Description : Crypt::DSA is an implementation of the DSA (Digital Signature Algorithm) signature verification system. This package provides DSA signing, signature verification, and key generation. DSA (Digital Signature Algorithm) signatures are no longer considered to be adequate for security. This module should only be used for verifying old signatures and should not be used for new signatures. That being said, some technologies still require DSA signatures even now. Consider using other solutions or explicitly not using DSA signatures. Crypt-DSA-GMP is a possible replacement. -------------------------------------------------------------------------------- Update Information: This update, to the current upstream release, addresses a cryptographic flaw (modulo bias) in key generation that could lead to private key compromise (CVE-2026-14570) . -------------------------------------------------------------------------------- ChangeLog: * Fri Jul 3 2026 Paul Howarth - 1.22-1 - Update to 1.22 - Hardening: Use a fresh, independent CSPRNG witness every round - Security fix: Modulo bias in key generation (CVE-2026-14570); an attack with hundreds of signatures could lead to full private-key compromise; keys should be considered compromised and new keys should be generated * Fri Jun 19 2026 Yaakov Selkowitz - 1.21-2 - Rebuilt for OpenSSL4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2497529 - CVE-2026-14570 perl-Crypt-DSA: Crypt::DSA: Private key recovery due to biased random number generation [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2497529 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-b77b9c5f04' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing . MGASA-2024-0089 - Updated gnutls packages fix security vulnerabilities Publication date: 26 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0089.html Type: security Affected Mageia releases: 9 CVE: CVE-2024-28834, CVE-2024-28835 The Minerva attack is a cryptographic vulnerability that exploits deterministic behavior in systems like GnuTLS, leading to side-channel leaks. In specific scenarios, such as when using the GNUTLS_PRIVKEY_FLAG_REPRODUCIBLE flag, it can result in a noticeable step in nonce size from 513 to 512 bits, exposing a potential timing side-channel. (CVE-2024-28834) A flaw has been discovered in GnuTLS where an application crash can be induced when attempting to verify a specially crafted .pem bundle using the "certtool --verify-chain" command. (CVE-2024-28835) References: - https://bugs.mageia.org/show_bug.cgi?id=32989 - http://www.slackware.com/security/viewer.php?l=slackware-security&y=2024&m=slackware-security.365688 - https://www.cve.org/CVERecord?id=CVE-2024-28834 - https://www.cve.org/CVERecord?id=CVE-2024-28835 SRPMS: - 9/core/gnutls-3.8.4-1.mga9 . OpenSSL patch resolves major vulnerabilities and mitigates information leakage risks, strengthening security across Arch Linux environments.. GnuTLS Security Update, Mageia Vulnerabilities, Timing Attack Mitigation. . Severity: Critical. LinuxSecurity.com Team
GnuPG could be made to incorrectly interpret the status of the cryptographic operation if it received specially crafted file.. =========================================================================Ubuntu Security Notice USN-3675-3 June 18, 2018 gnupg vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 12.04 ESM Summary: GnuPG could be made to incorrectly interpret the status of the cryptographic operation if it received specially crafted file. Software Description: - gnupg: GNU privacy guard - a free PGP replacement Details: USN-3675-1 fixed a vulnerability in GnuPG. This update provides the corresponding update for Ubuntu 12.04 ESM. Original advisory details: Marcus Brinkmann discovered that during decryption or verification, GnuPG did not properly filter out terminal sequences when reporting the original filename. An attacker could use this to specially craft a file that would cause an application parsing GnuPG output to incorrectly interpret the status of the cryptographic operation reported by GnuPG. (CVE-2018-12020) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 12.04 ESM: gnupg 1.4.11-3ubuntu2.11 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-3675-3 https://ubuntu.com/security/notices/USN-3675-1 CVE-2018-12020 . Ubuntu Security Notice USN-3675-3 June 18, 2018 gnupg vulnerability A security issue affects these r. gnupg, incorrectly, interpret, status, cryptographic, operation, receive. . Severity: Critical. LinuxSecurity.com Team
An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available. An update that fixes four vulnerabilities is now available.. SUSE Security Update: Security update for ntp ______________________________________________________________________________ Announcement ID: SUSE-SU-2015:0259-1 Rating: important References: #910764 #911792 Cross-References: CVE-2014-9293 CVE-2014-9294 CVE-2014-9297 CVE-2014-9298 Affected Products: SUSE Linux Enterprise Server 11 SP3 for VMware SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Desktop 11 SP3 ______________________________________________________________________________ An update that fixes four vulnerabilities is now available. Description: ntp has been updated to fix four security issues: * CVE-2014-9294: ntp-keygen used a weak RNG seed, which made it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. (bsc#910764) * CVE-2014-9293: The config_auth function, when an auth key is not configured, improperly generated a key, which made it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack. (bsc#910764) * CVE-2014-9298: ::1 can be spoofed on some operating systems, so ACLs based on IPv6 ::1 addresses could be bypassed. (bsc#910764) * CVE-2014-9297: vallen is not validated in several places in ntp_crypto.c, leading to potential information leak. (bsc#910764) Security Issues: * CVE-2014-9294 * CVE-2014-9293 * CVE-2014-9298 * CVE-2014-9297 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11 SP3 forVMware: zypper in -t patch slessp3-ntp=10293 - SUSE Linux Enterprise Server 11 SP3: zypper in -t patch slessp3-ntp=10293 - SUSE Linux Enterprise Desktop 11 SP3: zypper in -t patch sledsp3-ntp=10293 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Linux Enterprise Server 11 SP3 for VMware (i586 x86_64): ntp-4.2.4p8-1.29.32.1 ntp-doc-4.2.4p8-1.29.32.1 - SUSE Linux Enterprise Server 11 SP3 (i586 ia64 ppc64 s390x x86_64): ntp-4.2.4p8-1.29.32.1 ntp-doc-4.2.4p8-1.29.32.1 - SUSE Linux Enterprise Desktop 11 SP3 (i586 x86_64): ntp-4.2.4p8-1.29.32.1 ntp-doc-4.2.4p8-1.29.32.1 References: https://www.suse.com/security/cve/CVE-2014-9293.html https://www.suse.com/security/cve/CVE-2014-9294.html https://www.suse.com/security/cve/CVE-2014-9297.html https://www.suse.com/security/cve/CVE-2014-9298.html https://bugzilla.suse.com/show_bug.cgi?id=910764 https://bugzilla.suse.com/show_bug.cgi?id=911792 https://scc.suse.com:443/patches/ . A crucial revision for ntp on openSUSE addresses several significant vulnerabilities to boost overall system security.. SUSE Linux, NTP Issues, Security Updates, Remote Attacks. . Severity: Important. LinuxSecurity.com Team
It was discovered that BIND, an implementation of the DNS protocol suite, does not properly check the result of an OpenSSL function which is used to verify DSA cryptographic signatures. As a result, incorrect DNS resource records in zones protected by DNSSEC could be . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA-1703-1
Daniel Bleichenbacher discovered a flaw in GNU TLS cryptographic package that could allow an attacker to generate a forged signature that GNU TLS will accept as valid.. - --------------------------------------------------------------------------Debian Security Advisory DSA 1182-1
Tavis Ormandy discovered a flaw in the way GnuPG verifies cryptographically signed data with inline signatures. It is possible for an attacker to add unsigned text to a signed message in such a way so that when the signed text is extracted, the unsigned text is extracted as well, appearing as if it had been signed. The Common Vulnerabilities and Exposures project assigned the name CVE-2006-0049 to this issue.. ---------------------------------------------------------------------Fedora Update Notification FEDORA-2006-147 2006-03-13 ---------------------------------------------------------------------Product : Fedora Core 4 Name : gnupg Version : 1.4.2.2 Release : 1 Summary : A GNU utility for secure communication and data storage. Description : GnuPG (GNU Privacy Guard) is a GNU utility for encrypting data and creating digital signatures. GnuPG has advanced key management capabilities and is compliant with the proposed OpenPGP Internet standard described in RFC2440. Since GnuPG doesn't use any patented algorithm, it is not compatible with any version of PGP2 (PGP2.x uses only IDEA for symmetric-key encryption, which is patented worldwide). ---------------------------------------------------------------------Update Information: Tavis Ormandy discovered a flaw in the way GnuPG verifies cryptographically signed data with inline signatures. It is possible for an attacker to add unsigned text to a signed message in such a way so that when the signed text is extracted, the unsigned text is extracted as well, appearing as if it had been signed. The Common Vulnerabilities and Exposures project assigned the name CVE-2006-0049 to this issue. ---------------------------------------------------------------------* Fri Mar 10 2006 Nalin Dahyabhai - 1.4.2.2-1 - update to 1.4.2.2 to fix detection of unsigned data (CVE-2006-0049, #184557) ---------------------------------------------------------------------This update can bedownloaded from: 399347d86a34ec777de3fa46a8931774bf425679 SRPMS/gnupg-1.4.2.2-1.src.rpm a42396ca1e3828f725c903f3a38a03096bea3e91 ppc/gnupg-1.4.2.2-1.ppc.rpm d080a2ac636e7200970f7bca2cde0897d9949910 ppc/debug/gnupg-debuginfo-1.4.2.2-1.ppc.rpm 5f0cb70184126988f240c3487fe38ed37bae0df6 x86_64/gnupg-1.4.2.2-1.x86_64.rpm bc935e3520882a6461ddb27318fa909ebd9d47b4 x86_64/debug/gnupg-debuginfo-1.4.2.2-1.x86_64.rpm fa64b2b2645982e7abe49a2ca0ae85c899d65eff i386/gnupg-1.4.2.2-1.i386.rpm 8c146199cc14d0dbfaebbc2c4b8fbeb17e9589f1 i386/debug/gnupg-debuginfo-1.4.2.2-1.i386.rpm This update can be installed with the 'yum' update program. Use 'yum update package-name' at the command line. For more information, refer to 'Managing Software with yum,' available at . ----------------------------------------------------------------------- fedora-announce-list mailing list
Get the latest Linux and open source security news straight to your inbox.