SUSE-SU-2026:1954-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-20261954-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:1954-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2026:1954-1
Upstream
Related
Published
2026-05-18T07:55:02Z
Modified
2026-05-19T08:45:09Z
Summary
Security update for perl-Crypt-URandom
Details

This update for perl-Crypt-URandom fixes the following issue:

  • CVE-2026-2474: negative length parameter in the XS function can lead to a heap-based buffer overflow (bsc#1258266).

Changes for perl-Crypt-URandom:

  • updated to 0.550.0 (0.55)

  • Fix for sysread/read failures. Thanks to Miha Purg for GH#20

  • Fix for test suite failures on STDOUT encoding. Thanks to Lukas Mai for GH#19

References

Affected packages