Updated perl-Authen-SASL packages fix a security vulnerability
Publication date: 14 Sep 2026Modification date: 14 Sep 2026
Type: security
Affected Mageia releases : 10 , 9
CVE: CVE-2026-86219
Description
Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept
replayed authentication responses via unverified nonce in server_step.
(CVE-2026-86219)
References
- https://bugs.mageia.org/show_bug.cgi?id=36264
- https://www.openwall.com/lists/oss-security/2026/09/06/1
- https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L203-222
- https://metacpan.org/release/EHUELS/Authen-SASL-2.2000/source/lib/Authen/SASL/Perl/DIGEST_MD5.pm#L410-414
- https://datatracker.ietf.org/doc/html/rfc2831#section-2.1.2
- https://metacpan.org/release/EHUELS/Authen-SASL-2.2100/changes
- https://www.cve.org/CVERecord?id=CVE-2026-86219
SRPMS
10/core
- perl-Authen-SASL-2.190.0-1.1.mga10
9/core
- perl-Authen-SASL-2.160.0-13.2.mga9