| Name | CVE-2026-14570 |
| Description | Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce and private key from a biased random generator, leading to private-key recovery. "Crypt::DSA::Util::makerandom forces the high bit of every value it returns to obtain an exactly N-bit integer for prime search. The signing nonce and the private key are drawn from makerandom. Because the high bit is always set, the result is not uniform: its top bit is fixed, producing insecure values." An attacker who collects a modest number of signatures under an affected key, together with the public key, can recover the private key with a lattice attack. Keys used to sign with an affected version should be considered compromised and new keys should be generated. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
Vulnerable and fixed packages
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|
| libcrypt-dsa-perl (PTS) | bullseye | 1.17-4 | vulnerable |
| bookworm | 1.17-5 | vulnerable |
| trixie | 1.19-1 | vulnerable |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|
| libcrypt-dsa-perl | source | (unstable) | (unfixed) | | | |
Notes
[trixie] - libcrypt-dsa-perl <no-dsa> (Minor issue)
[bookworm] - libcrypt-dsa-perl <postponed> (Minor issue; biased makerandom nonce/key generation; obsolete leaf module, removed from sid)
[bullseye] - libcrypt-dsa-perl <postponed> (Minor issue; biased makerandom nonce/key generation; obsolete leaf module, removed from sid)
https://lists.security.metacpan.org/cve-announce/msg/41542402/