Bug 2494666 (CVE-2026-13758)
| Summary: | CVE-2026-13758 CryptX: CryptX for Perl: Message forgery via non-constant time AEAD tag comparison | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | medium | Docs Contact: | |
| Priority: | medium | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in CryptX for Perl. The library performs a non-constant time comparison of Authenticated Encryption with Associated Data (AEAD) authentication tags in its streaming decryption function. This timing difference creates a tag-verification oracle, allowing a remote attacker to submit multiple candidate tags and measure the timing. By exploiting this, an attacker can recover the expected tag byte by byte, leading to the forgery of messages that appear legitimate.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2494712, 2494713 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-06-29 21:02:27 UTC
|