CVE-2026-2474Patch(ddick / crypt\)

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch ddick crypt\ systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1) is supplied, the expression length + 1u causes an integer wraparound, resulting in a zero-byte allocation. The subsequent call to getrandom(data, length, GRND_NONBLOCK) passes the original negative value, which is implicitly converted to a large unsigned value (typically SIZE_MAX). This can result in writes beyond the allocated buffer, leading to heap memory corruption and application crash (denial of service). In common usage, the length argument is typically hardcoded by the caller, which reduces the likelihood of attacker-controlled exploitation. Applications that pass untrusted input to this parameter may be affected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crypt\

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-03-04)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
crypt\

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-16: 1Mentions · 2026-03-04: 2Patch / Workaround · 2026-03-04: 2Technical Details · 2026-02-16: 1Technical Details · 2026-03-04: 202-1603-04
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-161
Disclosure1
2026-03-042
Patch2
Full discourse3 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-2474 Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable to a heap buffer overflow in the XS function crypt_urandom_getrandom(). The function does not vali… https://www.cve.org/CVERecord?id=CVE-2026-2474

    Post summary

    The text provides a brief disclosure of a heap buffer overflow vulnerability in Crypt::URandom for Perl, specifying affected versions and the function involved.

    00010774
    56.4K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #Fedora 42: Critical perl-Crypt-URandom update (0.55) resolves CVE-2026-2474, a heap buffer overflow in crypt_urandom_getrandom(). Read more:👉 https://tinyurl.com/4bx2yx84 #Security https://t.co/IMne2kGpD9

    Post summary

    The Fedora 42 update patches CVE-2026-2474, a heap buffer overflow in perl-Crypt-URandom; no PoC, exploit code, or active exploitation is reported.

    0000044
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Fedora 42 and 43 ship fixes for perl-Crypt-URandom, addressing heap buffer overflow CVE-2026-2474 that could weaken non-blocking randomness on affected systems. #Linux https://threatcluster.io/cluster/fedora-perl-crypt-urandom-heap-buffer-overflow-fix-released-6d6ffd87

    Post summary

    Fedora 42 and 43 have released patches for the heap buffer overflow in perl‑Crypt‑URandom (CVE‑2026‑2474), addressing potential randomness weaknesses.

    0000029
    89 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appddickcrypt\\--

Explore more