CPANSA-Bytes-Random-Secure-2026-11625: Bytes-Random-Secure vulnerability

Publisher giterlizzi Document category csaf_security_advisory
Initial release date 2026-06-26T00:00:00 Engine CSAF Perl Toolkit 0.26
Current release date 2026-06-26T00:00:00 Build Date
Current version 1 Status final
CVSS v3.1 Base Score 7.5 Severity
Original language Language en
Also referred to

Vulnerability Description

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes. When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced. Secrets generated in multiprocess applications are predictable across processes.

Vulnerabilities

CVE-2026-11625

Vulnerability Description

Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes.

When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced.

Secrets generated in multiprocess applications are predictable across processes.

Weakness CWE-335 : Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)

Product status

Known affected
Product Score
Bytes-Random-Secure greater than 0
CVSS Version CVSS Vector CVSS Base Score CVSS Base Severity
3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 7.5 High

giterlizzi

Namespace: https://github.com/giterlizzi/

gdt@cpan.org

References

Revision history

Version Date of the revision Summary of the revision
1 Fri Jun 26 00:00:00 2026 First release

Sharing rules

TLP:WHITE
For the TLP version see: https://www.first.org/tlp/