Fedora alert FEDORA-2026-f4a6b0c635 (perl-Crypt-DSA)
| From: | updates--- via package-announce <package-announce@lists.fedoraproject.org> | |
| To: | package-announce@lists.fedoraproject.org | |
| Subject: | [SECURITY] Fedora 44 Update: perl-Crypt-DSA-1.21-1.fc44 | |
| Date: | Wed, 24 Jun 2026 01:30:53 +0000 | |
| Message-ID: | <20260624013053.F2AE777668@bastion01.rdu3.fedoraproject.org> | |
| Archive-link: | Article |
-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2026-f4a6b0c635 2026-06-24 01:28:48.584512+00:00 -------------------------------------------------------------------------------- Name : perl-Crypt-DSA Product : Fedora 44 Version : 1.21 Release : 1.fc44 URL : https://metacpan.org/release/Crypt-DSA Summary : Perl module for DSA signatures and key generation Description : Crypt::DSA is an implementation of the DSA (Digital Signature Algorithm) signature verification system. This package provides DSA signing, signature verification, and key generation. DSA (Digital Signature Algorithm) signatures are no longer considered to be adequate for security. This module should only be used for verifying old signatures and should not be used for new signatures. That being said, some technologies still require DSA signatures even now. Consider using other solutions or explicitly not using DSA signatures. Crypt-DSA-GMP is a possible replacement. -------------------------------------------------------------------------------- Update Information: This update, to the current upstream release, prevents key material reuse for multiple signing events (CVE-2026-12205, CWE-323). -------------------------------------------------------------------------------- ChangeLog: * Mon Jun 15 2026 Paul Howarth <paul@city-fan.org> - 1.21-1 - Update to 1.21 - Fixed key material reuse for multiple signing events (CVE-2026-12205, CWE-323) - sign() reused the DSA nonce k across signatures (r and k^-1 were cached on the key and not regenerated), allowing private-key recovery from two signatures over different messages - Now generates a fresh nonce per signature - Keys used to sign more than once with an affected version should be considered compromised * Fri Jun 12 2026 Yaakov Selkowitz <yselkowi@redhat.com> - 1.20-2 - Rebuilt for openssl 4.0 -------------------------------------------------------------------------------- References: [ 1 ] Bug #2491340 - CVE-2026-12205 perl-Crypt-DSA: Crypt::DSA: Private-key recovery via nonce reuse across signatures [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2491340 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-f4a6b0c635' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- -- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-cond... List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines List Archives: https://lists.fedoraproject.org/archives/list/package-ann... Do not reply to spam, report it: https://forge.fedoraproject.org/infra/tickets/issues/new
