librnp uses weak random number generation such that generated keys can be easily cracked.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202511-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: librnp: Weak random number generation Date: November 26, 2025 Bugs: #966299 ID: 202511-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== librnp uses weak random number generation such that generated keys can be easily cracked. Background ========== librnp is a high performance C++ OpenPGP library. Affected packages ================= Package Vulnerable Unaffected --------------- ------------ ------------ dev-util/librnp = 0.18.0 > = 0.18.1 Description =========== The affected librnp version generated weak session keys for its public key encryption (PKESK) mode. Impact ====== Messages encrypted using the affected librnp version might be readable by an attacker with just the public key. Workaround ========== There is no known workaround at this time. Resolution ========== All librnp users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-util/librnp-0.18.1" If sensitive information was sent using e.g. Thunderbird (with USE=system-librnp, the default), it should be considered potentially viewable by an attacker. References ========== [ 1 ] CVE-2025-13470 https://nvd.nist.gov/vuln/detail/CVE-2025-13470 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202511-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users'machines is of utmost importance to us. Any security concerns should be addressed to
An update that solves 2 vulnerabilities can now be installed.. # librnp0-0.18.1-1.1 on GA media Announcement ID: openSUSE-SU-2025:15762-1 Rating: moderate Cross-References: * CVE-2025-13402 * CVE-2025-13470 Affected Products: * openSUSE Tumbleweed An update that solves 2 vulnerabilities can now be installed. ## Description: These are all security issues fixed in the librnp0-0.18.1-1.1 package on the GA media of openSUSE Tumbleweed. ## Package List: * openSUSE Tumbleweed: * librnp0 0.18.1-1.1 * rnp 0.18.1-1.1 * rnp-devel 0.18.1-1.1 ## References: * https://www.suse.com/security/cve/CVE-2025-13402.html * https://www.suse.com/security/cve/CVE-2025-13470.html . Update released for openSUSE Tumbleweed addressing 2 moderate severity issues in librnp0 package with proper fixes.. openSUSE Tumbleweed Update, librnp0 vulnerabilities, moderate severity issues. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.