librnp uses weak random number generation such that generated keys can be easily cracked.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202511-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: librnp: Weak random number generation Date: November 26, 2025 Bugs: #966299 ID: 202511-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== librnp uses weak random number generation such that generated keys can be easily cracked. Background ========== librnp is a high performance C++ OpenPGP library. Affected packages ================= Package Vulnerable Unaffected --------------- ------------ ------------ dev-util/librnp = 0.18.0 > = 0.18.1 Description =========== The affected librnp version generated weak session keys for its public key encryption (PKESK) mode. Impact ====== Messages encrypted using the affected librnp version might be readable by an attacker with just the public key. Workaround ========== There is no known workaround at this time. Resolution ========== All librnp users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-util/librnp-0.18.1" If sensitive information was sent using e.g. Thunderbird (with USE=system-librnp, the default), it should be considered potentially viewable by an attacker. References ========== [ 1 ] CVE-2025-13470 https://nvd.nist.gov/vuln/detail/CVE-2025-13470 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202511-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users'machines is of utmost importance to us. Any security concerns should be addressed to
Get the latest Linux and open source security news straight to your inbox.