Junglewise Threat Intelligence

CVE-2026-41564: CryptX PRNG state reuse after fork in Crypt::PK modules

CVE-2026-41564 · Severity: high · CVSS 7.5 · Published 2026-04-23

Executive brief

CryptX is a popular Perl library used for cryptographic operations like generating digital signatures and encryption keys. A security flaw in older versions allows different server processes to generate identical security keys or signatures if they were started from the same parent process. This could allow an attacker to recover secret private keys, potentially leading to unauthorized access or the ability to impersonate the affected service.

Technical details

The Crypt::PK modules (including RSA, DSA, DH, ECC, Ed25519, and X25519) in CryptX versions prior to 0.088 fail to detect process forking. Because the Pseudo-Random Number Generator (PRNG) state is seeded only during the object constructor, child processes created via fork() inherit a byte-identical PRNG state. This lack of entropy reseeding means that randomized operations, such as key generation or signature creation, can produce identical outputs across different processes. In the case of DSA or ECDSA, reusing a nonce across two different signatures is sufficient for an attacker to mathematically recover the private signing key. This is particularly critical for preforking web servers like Starman. The issue is resolved in version 0.088 by implementing fork detection and reseeding.

Affected products

  • DCIT CryptX < 0.088

Timeline

  • 2026-04-18: disclosed: Issue discovered by CPANSec
  • 2026-04-21: other: Reported to upstream maintainer
  • 2026-04-23: patched: CryptX 0.088 released with fix
  • 2026-04-23: advisory: Public advisory published

References