CVE-2026-11625

EUVD-2026-39640
Bytes::Random::Secure versions through 0.29 for Perl share internal state across forked processes.

When an object is initialised before forking, or when the functional interface is used, then the internal state for the PRNG is shared across processes and identical random streams will be produced.

Secrets generated in multiprocess applications are predictable across processes.
PRNG
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 26.51%
Debian logo
Debian Releases
Debian Product
Codename
libbytes-random-secure-perl
bookworm
0.29-4~deb13u1~deb12u1
fixed
bullseye
postponed
forky
0.29-4
fixed
sid
0.29-4
fixed
trixie
0.29-4~deb13u1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libbytes-random-secure-perl
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
questing
ignored
resolute
needs-triage
trusty
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
perl-Bytes-Random-Secure
Azure Linux 3.0
0:0.29-22.azl3
fixed