Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-0577

Опубликовано: 23 янв. 2025
Источник: redhat
CVSS3: 4.8
EPSS Низкий

Описание

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.

Отчет

This flaw only affected a limited subset of glibc versions present in Fedora 40 (glibc-2.39-28.fc40 and glibc-2.39-33.fc40), Fedora 41 (glibc-2.40-12.fc41 and glibc-2.40-17.fc41) and CentOS 10 Stream (glibc-2.39-29.el10 to glibc-2.39-33.el10).

Меры по смягчению последствий

Red Hat Product Security does not have any mitigation recommendations at this time.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10glibcNot affected
Red Hat Enterprise Linux 6glibcNot affected
Red Hat Enterprise Linux 7glibcNot affected
Red Hat Enterprise Linux 8glibcNot affected
Red Hat Enterprise Linux 9glibcNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-331
https://bugzilla.redhat.com/show_bug.cgi?id=2338871glibc: vDSO getrandom acceleration may return predictable randomness

EPSS

Процентиль: 16%
0.00244
Низкий

4.8 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
6 месяцев назад

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.

CVSS3: 4.8
nvd
6 месяцев назад

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.

CVSS3: 4.8
debian
6 месяцев назад

An insufficient entropy vulnerability was found in glibc. The getrando ...

CVSS3: 4.8
github
6 месяцев назад

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.

EPSS

Процентиль: 16%
0.00244
Низкий

4.8 Medium

CVSS3

Уязвимость CVE-2025-0577