An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.
History

Wed, 18 Feb 2026 20:45:00 +0000

Type Values Removed Values Added
Title glibc: vDSO getrandom acceleration may return predictable randomness Glibc: vdso getrandom acceleration may return predictable randomness
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References

Fri, 24 Jan 2025 01:45:00 +0000

Type Values Removed Values Added
Description An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.
Title glibc: vDSO getrandom acceleration may return predictable randomness
Weaknesses CWE-331
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


cve-icon MITRE

Status: PUBLISHED

Assigner: fedora

Published:

Updated: 2026-02-18T20:25:34.864Z

Reserved: 2025-01-19T13:43:18.289Z

Link: CVE-2025-0577

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-02-18T21:16:20.010

Modified: 2026-02-18T21:16:20.010

Link: CVE-2025-0577

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-01-23T22:40:05Z

Links: CVE-2025-0577 - Bugzilla

cve-icon OpenCVE Enrichment

No data.