CVE-2026-2597Disclosure(leont / crypt\)

LOWCVSS 7.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch leont crypt\ systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_bytes(). The function does not validate that the length parameter is non-negative. If a negative value (e.g. -1) is supplied, the expression length + 1u causes an integer wraparound, resulting in a zero-byte allocation. The subsequent call to chosen random function (e.g. getrandom) passes the original negative value, which is implicitly converted to a large unsigned value (typically SIZE_MAX). This can result in writes beyond the allocated buffer, leading to heap memory corruption and application crash (denial of service). In common usage, the length argument is typically hardcoded by the caller, which reduces the likelihood of attacker-controlled exploitation. Applications that pass untrusted input to this parameter may be affected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122CWE-1284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • crypt\

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-03-11)
  • 6 total mentions across 4 days

Affected systems

Vendors
Products
crypt\

1 version affected across 1 product

Deep dive

Activity timeline6 mentions / 4d
01223Mentions · 2026-02-27: 1Mentions · 2026-03-03: 1Mentions · 2026-03-04: 1Mentions · 2026-03-11: 3Patch / Workaround · 2026-03-11: 3Technical Details · 2026-02-27: 1Technical Details · 2026-03-03: 1Technical Details · 2026-03-04: 1Technical Details · 2026-03-11: 202-2703-0303-0403-11
Signal classification2 categories
Disclosure
350.0%
Patch
350.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-271
Disclosure1
2026-03-031
Disclosure1
2026-03-041
Disclosure1
2026-03-113
Patch3
Full discourse6 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Heads up, #Fedora 43 community! 🐧 A critical patch for perl-Crypt-SysRandom-XS (CVE-2026-2597) just dropped. Read more: 👉 https://tinyurl.com/4e7xuxsk #Security https://t.co/rO7XYZyeNp

    Post summary

    A critical patch for perl-Crypt-SysRandom-XS (CVE-2026-2597) has been released for Fedora 43 users, with no mention of PoC, exploit tools, active exploitation, or false positives.

    0001040
    1.3K followersView on X
  • ThreatCluster@threatcluster
    Patch

    Ubuntu 23 and Fedora 43 report critical buffer overflow flaws in cryptographic random-data modules (CVE-2026-2597), potentially exposing systems to exploitation. Patch updates now. #Linux https://threatcluster.io/cluster/critical-buffer-overflow-vulnerabilities-in-ubuntu-and-fedor-a1a6c6a8

    Post summary

    The post reports a critical buffer‑overflow vulnerability (CVE‑2026‑2597) in Ubuntu 23 and Fedora 43’s random‑data modules and notes that patch updates are now available.

    0001059
    99 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Just a heads-up for the #Fedora sysadmins on here: There's a new patch out for CVE-2026-2597 (perl-Crypt-SysRandom-XS). Read more: 👉 https://tinyurl.com/2a88r4dd #Security https://t.co/31dddnnmkB

    Post summary

    A new patch for CVE-2026-2597, affecting the perl-Crypt-SysRandom-XS module, has been released to Fedora sysadmins.

    0000039
    1.3K followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2597 (CVSS:7.5, HIGH) is Analyzed. Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by..https://nvd.nist.gov/vuln/detail/CVE-2026-2597 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-2597, a heap buffer overflow in Crypt::SysRandom::XS before 0.010, with a CVSS score of 7.5, but provides no PoC, exploit, or patch details.

    0000018
    173 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-2597 (CVSS:7.5, HIGH) is Undergoing Analysis. Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_by..https://nvd.nist.gov/vuln/detail/CVE-2026-2597 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-2597, a heap buffer overflow in Crypt::SysRandom::XS before 0.010, with CVSS 7.5, and notes it is under analysis.

    0000039
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-2597 Crypt::SysRandom::XS versions before 0.010 for Perl is vulnerable to a heap buffer overflow in the XS function random_bytes(). The function does not validate that the … https://www.cve.org/CVERecord?id=CVE-2026-2597

    Post summary

    The CVE-2026-2597 vulnerability in Crypt::SysRandom::XS before 0.010 causes a heap buffer overflow in the random_bytes() function, with no PoC, exploit, patch, or evidence of active exploitation mentioned.

    00000125
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appleontcrypt\\--

Explore more