DEBIAN-CVE-2026-12205

Source
https://security-tracker.debian.org/tracker/CVE-2026-12205
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-12205.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-12205
Upstream
Published
2026-06-15T23:16:43Z
Modified
2026-09-14T17:01:44Z
Severity
  • 9.1 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N CVSS Calculator
Summary
[none]
Details

Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object without ever clearing it. The first sign() on a Key object picks a nonce, and every later sign() on that same object reuses it, producing an identical "r". Keys used to sign more than once with an affected version should be considered compromised.

References

Affected packages

Debian:12 / libcrypt-dsa-perl

Package

Name
libcrypt-dsa-perl
Purl
pkg:deb/debian/libcrypt-dsa-perl?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.17-5
1.19-1
1.20-1
1.21-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-12205.json"

Debian:13 / libcrypt-dsa-perl

Package

Name
libcrypt-dsa-perl
Purl
pkg:deb/debian/libcrypt-dsa-perl?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.19-1
1.20-1
1.21-1

Ecosystem specific

{
    "urgency":  "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-12205.json"