Home
MEDIUM: 4.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:NDefault status
unaffected
2.39-28.fc40 (semver)
affected
2.40-12.fc41 (semver)
affected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Default status
unaffected
Description
An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.
Problem types
Product status
2.39-28.fc40 (semver)
2.40-12.fc41 (semver)
Timeline
| 2025-01-19: | Reported to Red Hat. |
| 2025-01-23: | Made public. |
References
access.redhat.com/security/cve/CVE-2025-0577
bugzilla.redhat.com/show_bug.cgi?id=2338871 (RHBZ#2338871)