Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-40109

Опубликовано: 09 нояб. 2025
Источник: redhat
CVSS3: 5.5

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: rng - Ensure set_ent is always present Ensure that set_ent is always set since only drbg provides it.

A flaw was found in the Linux kernel’s cryptographic random number generation (RNG) code where the set_ent routine, responsible for incorporating additional entropy, was not guaranteed to be present except in the deterministic random bit generator (DRBG) implementation. This could result in incomplete entropy mixing in non-DRBG RNG paths, weakening randomness used for cryptographic operations. Although exploitation requires local access and does not directly lead to privilege escalation, inadequate randomness can compromise cryptographic strength and potentially lead to system instability or weakened security guarantees

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10kernelFix deferred
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelFix deferred
Red Hat Enterprise Linux 9kernel-rtFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-331
https://bugzilla.redhat.com/show_bug.cgi?id=2413619kernel: Linux kernel: Denial of Service in crypto random number generator due to missing set_ent

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: crypto: rng - Ensure set_ent is always present Ensure that set_ent is always set since only drbg provides it.

nvd
5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: crypto: rng - Ensure set_ent is always present Ensure that set_ent is always set since only drbg provides it.

CVSS3: 4.2
msrc
5 месяцев назад

crypto: rng - Ensure set_ent is always present

debian
5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: c ...

github
5 месяцев назад

In the Linux kernel, the following vulnerability has been resolved: crypto: rng - Ensure set_ent is always present Ensure that set_ent is always set since only drbg provides it.

5.5 Medium

CVSS3