Fedora has issued an advisory on January 15: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GLAEBHWU2NBVEDHXVVKYY4Y2XLNJX2VX/
Whiteboard: (none) => MGA9TOOStatus comment: (none) => Fixed upstream in 0.30CVE: (none) => CVE-2025-22376Source RPM: (none) => perl-Net-OAuth-0.280.0-11.mga9.src.rpm
ThierryV has just put v0.30 in Cauldron. Hopefully it will do for M9 also.
Assignee: bugsquad => perl
Version: Cauldron => 9Whiteboard: MGA9TOO => (none)
Suggested advisory: ======================== The updated packages fix a security vulnerability: In Net::OAuth::Client in the Net::OAuth package before 0.29 for Perl, the default nonce is a 32-bit integer generated from the built-in rand() function, which is not cryptographically strong. (CVE-2025-22376) References: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/GLAEBHWU2NBVEDHXVVKYY4Y2XLNJX2VX/ ======================== Updated packages in core/updates_testing: ======================== perl-Crypt-URandom-0.370.0-1.mga9 perl-Module-Build-0.423.400-1.mga9 perl-Net-OAuth-0.300.0-1.mga9 from SRPMS: perl-Crypt-URandom-0.370.0-1.mga9.src.rpm perl-Module-Build-0.423.400-1.mga9.src.rpm perl-Net-OAuth-0.300.0-1.mga9.src.rpm
Status comment: Fixed upstream in 0.30 => (none)Status: NEW => ASSIGNEDAssignee: perl => qa-bugs
Keywords: (none) => advisory
RH x86_64 installing perl-Module-Build-0.423.400-1.mga9.noarch.rpm perl-Crypt-URandom-0.370.0-1.mga9.noarch.rpm perl-Net-OAuth-0.300.0-1.mga9.noarch.rpm from //home/katnatek/qa-testing/x86_64 Preparing... ################################################################################################## 1/3: perl-Crypt-URandom ################################################################################################## 2/3: perl-Net-OAuth ################################################################################################## 3/3: perl-Module-Build ################################################################################################## 1/2: removing perl-Net-OAuth-0.280.0-11.mga9.noarch ################################################################################################## 2/2: removing perl-Module-Build-1:0.423.200-1.mga9.noarch ################################################################################################## Clean install
MGA9-64 Plasma Wayland on Compaq H000SB No installation issues. Indeed clean install for this developer stuff.
CC: (none) => herman.viaeneWhiteboard: (none) => MGA9-64-OK
Validating.
Keywords: (none) => validated_updateCC: (none) => andrewsfarm, sysadmin-bugs
An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2025-0062.html
Resolution: (none) => FIXEDStatus: ASSIGNED => RESOLVED