Debian 12 Urwid Vulnerability Alert DLA-4780-1 CVE-2026-9323 Details

SecurityVulns

The urwid web display backend generates web session identifiers by concatenating two random.randrange(10**9) calls that use Python’s Mersenne Twister PRNG, which is not cryptographically secure. The same identifier is also used as the filename of a FIFO created in the world-listable /tmp directory, so any local user on the host can listLinuxSecurity – Security AdvisoriesRead More