DEBIAN-CVE-2026-11625

Source
https://security-tracker.debian.org/tracker/CVE-2026-11625
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-11625.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-11625
Upstream
Published
2026-06-26T09:16:33Z
Modified
2026-09-14T17:01:40Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are predictable across processes.

References

Affected packages

Debian:12 / libbytes-random-secure-perl

Package

Name
libbytes-random-secure-perl
Purl
pkg:deb/debian/libbytes-random-secure-perl?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.29-4~deb13u1~deb12u1

Affected versions

0.*
0.29-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-11625.json"

Debian:13 / libbytes-random-secure-perl

Package

Name
libbytes-random-secure-perl
Purl
pkg:deb/debian/libbytes-random-secure-perl?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.29-4~deb13u1

Affected versions

0.*
0.29-3
0.29-4~deb13u1~deb12u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-11625.json"

Debian:14 / libbytes-random-secure-perl

Package

Name
libbytes-random-secure-perl
Purl
pkg:deb/debian/libbytes-random-secure-perl?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.29-4

Affected versions

0.*
0.29-3
0.29-4~deb13u1~deb12u1
0.29-4~deb13u1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-11625.json"