ELBA-2026-67470

ELBA-2026-67470 - perl-Crypt-PBKDF2 Bug Fix update

Type:BUG
Impact:NA
Release Date:2026-07-14

Description


[0.261630-1]
- Update to 0.261630 (rhbz#2488228)
- Change the default hash algorithm to HMAC-SHA256, and increase the default
number of iterations to 600,000, in line with current OWASP recommendations
(CVE-2026-9641)
- Generate salts using Crypt::URandom (a strong system RNG) instead of perl's
builtin rand(), which is not cryptographically secure (CVE-2026-9638)
- Use a constant-time comparison in 'validate' to avoid timing attacks
(CVE-2017-20240)
- Switch to Module::Build::Tiny flow
- Package new README file

[0.161520-25]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_44_Mass_Rebuild

[0.161520-24]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_43_Mass_Rebuild

[0.161520-23]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_42_Mass_Rebuild

[0.161520-22]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_41_Mass_Rebuild

[0.161520-21]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

[0.161520-20]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_40_Mass_Rebuild

[0.161520-19]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild

[0.161520-18]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild

[0.161520-17]
- Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild




Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 8 (x86_64) perl-Crypt-PBKDF2-0.261630-1.el8.src.rpm7fefaba34f9fd4c377e2d27f2120af13d230d27c4cfef2a4f1b94705a08e0718-ol8_x86_64_developer_EPEL
perl-Crypt-PBKDF2-0.261630-1.el8.noarch.rpm060c90de387d25cdc40c5597040fe384cd118da0040634ef5a050a4dcdba9c41-ol8_x86_64_developer_EPEL



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete