Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91571.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-91571
Upstream
Published
2026-06-26T09:16:33Z
Modified
2026-08-29T05:27:27Z
Summary
CVE-2026-11625 affecting package perl-Bytes-Random-Secure for versions less than 0.29-22
Details

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes.

When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced.

Secrets generated in multiprocess applications are predictable across processes.

References

Affected packages

Azure Linux:3 / perl-Bytes-Random-Secure

Package

Name
perl-Bytes-Random-Secure
Purl
pkg:rpm/azure-linux/perl-Bytes-Random-Secure

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.29-22

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-91571.json"