Gentoo alert 202511-07 (librnp)
| From: | glsamaker@gentoo.org | |
| To: | gentoo-announce@lists.gentoo.org | |
| Subject: | [gentoo-announce] [ GLSA 202511-07 ] librnp: Weak random number generation | |
| Date: | Wed, 26 Nov 2025 00:25:34 -0000 | |
| Message-ID: | <176411673466.7.14678136197881110962@3f85d36892cf> |
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 202511-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: High Title: librnp: Weak random number generation Date: November 26, 2025 Bugs: #966299 ID: 202511-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======== librnp uses weak random number generation such that generated keys can be easily cracked. Background ========== librnp is a high performance C++ OpenPGP library. Affected packages ================= Package Vulnerable Unaffected --------------- ------------ ------------ dev-util/librnp = 0.18.0 >= 0.18.1 Description =========== The affected librnp version generated weak session keys for its public key encryption (PKESK) mode. Impact ====== Messages encrypted using the affected librnp version might be readable by an attacker with just the public key. Workaround ========== There is no known workaround at this time. Resolution ========== All librnp users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-util/librnp-0.18.1" If sensitive information was sent using e.g. Thunderbird (with USE=system-librnp, the default), it should be considered potentially viewable by an attacker. References ========== [ 1 ] CVE-2025-13470 https://nvd.nist.gov/vuln/detail/CVE-2025-13470 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/202511-07 Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2025 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEpqTA6ABLMxh/aChGFMQkOaVy+9kFAmkmSP4ACgkQFMQkOaVy +9nsthAAhey2rI3kA9uBgAY6RolOxUCE6FZ9TxNsf1SC2rdsaPkRFfrn4eObJaHn SN90BePtnevzwYjP1Uy4KvbyYPWpiAmKkwdXjTIPXK0ejJWmhppLurzkcxRUckzA 47YINt56LVUi7Qy7RhuWAcJvKmeQohhcU13PBzZpvGfEDMjMulaMdtL57g0V+cRm yYZio2DBDXLdFQgFXBsrScPlXSHLImOtxOh9M+s/qXZsYRSKaATapg0dWaL20+tI n/GRRnM7E3SBP97PLN+i/6jI766rhmdiGulOz6JJiW1hyRrcTzk6Y1EhRVc4vsVr IIdzUOHxqv0BGgTAIGPcSx0AefolZwBkO9F7fGrypHnjY9XSR+l74QHvRQ3CahrM U9eyGfJCDXlzRo780knVIowaWCy7d7JKFUQTFTyvq8NDcqbb515JIrqoio3l51hq Vt5uhe73VJmzf2zYQ24Wy2tci2swd10l/z57uygyE6V+9X+WKnn7Lzw5gfT/rer7 hv+fwXBd3oVzEqTAj/as3a/2GWV6RE8fOTO5p6zg1HA5z65PIHtxUh1xAXn2W+5T yagw3t6YcDs4LLvIzBFa58TxCUQqOjFunUvTjVYOmvCE4OHRPvivdjJMzRXA+3Ih Rvy3wXDEZyPdyXEHmvgqWVgnWVxOU0NMQ2sq+gMQ+CRI1ypAF4E= =zQ4y -----END PGP SIGNATURE-----
