PT-2025-30102 · Wolfssl+1 · Wolfssl+1
Per Allansson
·
Published
2025-07-18
·
Updated
2026-01-15
·
CVE-2025-7394
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
wolfSSL (affected versions not specified)
Description
The OpenSSL compatibility layer implementation had an issue with the
RAND poll() function, potentially leading to predictable values returned from RAND bytes() after a fork() call. This could result in weak or predictable random numbers in applications using RAND bytes() and performing fork() operations. The issue does not affect internal TLS operations. A code change was implemented to reseed the Hash-DRBG after detecting a new process, similar to OpenSSL’s behavior.Recommendations
Update to the latest version of wolfSSL.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Wolfssl