3Corns

USN-8418-1: Crypt-SaltedHash vulnerability - Ubuntu

It was discovered that Crypt-SaltedHash incorrectly generated salts using a cryptographically weak pseudo-random number generator. An attacker could possibly use this issue to predict generated salts, leading to a weakening of cryptographic protections. Packages that are affected: libcrypt-saltedhash-perl - module for handling salted hashes affecting the following:

Packages affected:
# UBUNTU RELEASE PACKAGE VERSION -
1 26.04 LTS resolute libcrypt-saltedhash-perl 0.09-3ubuntu0.26.04.1~esm1
2 25.10 LTS questing libcrypt-saltedhash-perl 0.09-3ubuntu0.25.10.1~esm1
3 24.04 LTS noble libcrypt-saltedhash-perl 0.09-3ubuntu0.24.04.1~esml
4 24.04 LTS jammy libcrypt-saltedhash-perl 0.09-1.1ubuntu0.1~esm1
5 20.04 focal noble libcrypt-saltedhash-perl 0.09-1ubuntu0.20.04.1~esm1
6 18.04 LTS bionic libcrypt-saltedhash-perl 0.09-1ubuntu0.18.04.1~esm1
7 16.06 xenial noble libcrypt-saltedhash-perl 0.09-1ubuntu0.16.04.1~esm1

🔗 Cited Information: https://ubuntu.com/security/CVE-2026-47372, https://ubuntu.com/security/notices/USN-8418-1#details


Articles | Timewaster

Home | About 3Corns

3corns