Vulnerability Bulletins

CVE-2026-5086

   
Affected software LINUX SUSE
 
Crypt::SecretBuffer versions before 0.019 for Perl is suseceptible to timing attacks.

For example, if Crypt::SecretBuffer was used to store and compare plaintext passwords, then discrepencies in timing could be used to guess the secret password.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-5086