0.088 2026-04-23 - Crypt::KeyDerivation - new functions: pbkdf1_openssl, bcrypt_pbkdf, scrypt_pbkdf, argon2_pbkdf - Crypt::Misc - new functions: random_v7uuid, is_uuid - bundled libtomcrypt update branch:develop (commit: 2e441a17. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-bc5090f99b 2026-05-02 01:57:11.713683+00:00 -------------------------------------------------------------------------------- Name : perl-CryptX Product : Fedora 42 Version : 0.088 Release : 2.fc42 URL : https://metacpan.org/release/CryptX Summary : Cryptographic toolkit Description : This Perl library provides a cryptography based on LibTomCrypt library. -------------------------------------------------------------------------------- Update Information: 0.088 2026-04-23 - Crypt::KeyDerivation - new functions: pbkdf1_openssl, bcrypt_pbkdf, scrypt_pbkdf, argon2_pbkdf - Crypt::Misc - new functions: random_v7uuid, is_uuid - bundled libtomcrypt update branch:develop (commit: 2e441a17 2026-04-15) - bundled libtommath update branch:develop (commit: ae40a87 2026-04-20) - security fix CVE-2026-41564 https://github.com/DCIT/perl- CryptX/security/advisories/GHSA-24c2-gp6c-24c6 -------------------------------------------------------------------------------- ChangeLog: * Thu Apr 23 2026 Xavier Bachelot - 0.088-2 - Add missing BR: perl(Time::HiRes) * Thu Apr 23 2026 Xavier Bachelot - 0.088-1 - Update to 0.088 (RHBZ#22461073) - Fix CVE-2026-41564 (RHBZ#2461084,RHBZ#2461085) * Sat Jan 17 2026 Fedora Release Engineering - 0.087-5 - Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild * Fri Jul 25 2025 Fedora Release Engineering - 0.087-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild * Mon Jul 7 2025 Jitka Plesnikova - 0.087-3 - Perl 5.42rebuild -------------------------------------------------------------------------------- References: [ 1 ] Bug #2461085 - CVE-2026-41564 perl-CryptX: CryptX: Private key recovery due to predictable pseudo-random number generation after forking [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2461085 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bc5090f99b' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list --
- Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408) - Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373) - Fix two-key 3DES (PR #390) - Fix accelerated CTR mode (PR #359) - Fix Fortuna PRNG (PR #363) - Fix compilation on platforms where cc doesn't point to gcc (PR #382) - Fix using the wrong environment variable LT instead of LIBTOOL (PR #392) - Fix [More...]. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-9d667bdff8 2018-07-19 18:02:50.871311 --------------------------------------------------------------------------------Name : libtomcrypt Product : Fedora 28 Version : 1.18.2 Release : 1.fc28 URL : https://www.libtom.net/ Summary : A comprehensive, portable cryptographic toolkit Description : A comprehensive, modular and portable cryptographic toolkit that provides developers with a vast array of well known published block ciphers, one-way hash functions, chaining modes, pseudo-random number generators, public key cryptography and a plethora of other routines. Designed from the ground up to be very simple to use. It has a modular and standard API that allows new ciphers, hashes and PRNGs to be added or removed without change to the overall end application. It features easy to use functions and a complete user manual which has many source snippet examples. --------------------------------------------------------------------------------Update Information: - Fix Side Channel Based ECDSA Key Extraction (CVE-2018-12437) (PR #408) - Fix potential stack overflow when DER flexi-decoding (CVE-2018-0739) (PR #373) - Fix two-key 3DES (PR #390) - Fix accelerated CTR mode (PR #359) - Fix Fortuna PRNG (PR #363) - Fix compilation on platforms where cc doesn't point to gcc (PR #382) - Fix using the wrong environment variable LT instead of LIBTOOL (PR #392) - Fix build on platforms where the compiler provides __WCHAR_MAX__ but wchar.h isnot available (PR #390) - Fix & re-factor crypt_list_all_sizes() and crypt_list_all_constants() (PR #414) - Minor fixes (PR's #350 #351 #375 #377 #378 #379) --------------------------------------------------------------------------------ChangeLog: * Sun Jul 8 2018 Simone Caronni - 1.18.2-1 - Udpate to 1.18.2. * Wed Apr 18 2018 Simone Caronni - 1.18.1-5 - Update build requirement for texlive rebase. * Mon Apr 9 2018 Rafael Santos - 1.18.1-4 - Fix missing Fedora linker flags (bug #1548709) --------------------------------------------------------------------------------References: [ 1 ] Bug #1591906 - CVE-2018-12437 libtomcrypt: memory-cache side-channel attack on ECDSA signatures [epel-all] https://bugzilla.redhat.com/show_bug.cgi?id=1591906 [ 2 ] Bug #1591905 - CVE-2018-12437 libtomcrypt: memory-cache side-channel attack on ECDSA signatures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1591905 [ 3 ] Bug #1548709 - libtomcrypt: Partial build flags injection https://bugzilla.redhat.com/show_bug.cgi?id=1548709 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-9d667bdff8' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.