CVE-2007-2453
Last modified
CVE-2007-2453 is a vulnerability of currently unknown severity. The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source.. EPSS estimates a 0.38% chance of exploitation in the next 30 days.
Description
The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | 2.6.0 |
| Linux | Linux Kernel | 2.6.1 |
| Linux | Linux Kernel | 2.6.2 |
| Linux | Linux Kernel | 2.6.3 |
| Linux | Linux Kernel | 2.6.4 |
| Linux | Linux Kernel | 2.6.5 |
| Linux | Linux Kernel | 2.6.6 |
| Linux | Linux Kernel | 2.6.7 |
| Linux | Linux Kernel | 2.6.8 |
| Linux | Linux Kernel | 2.6.8.1 |
| Linux | Linux Kernel | 2.6.8.1.5 |
| Linux | Linux Kernel | 2.6.9 |
| Linux | Linux Kernel | 2.6.10 |
| Linux | Linux Kernel | 2.6.11 |
| Linux | Linux Kernel | 2.6.11.1 |
| Linux | Linux Kernel | 2.6.11.2 |
| Linux | Linux Kernel | 2.6.11.3 |
| Linux | Linux Kernel | 2.6.11.4 |
| Linux | Linux Kernel | 2.6.11.5 |
| Linux | Linux Kernel | 2.6.11.6 |
| Linux | Linux Kernel | 2.6.11.7 |
| Linux | Linux Kernel | 2.6.11.8 |
| Linux | Linux Kernel | 2.6.11.9 |
| Linux | Linux Kernel | 2.6.11.10 |
| Linux | Linux Kernel | 2.6.11.11 |
| Linux | Linux Kernel | 2.6.11.12 |
| Linux | Linux Kernel | 2.6.11_rc1_bk6 |
| Linux | Linux Kernel | 2.6.12 |
| Linux | Linux Kernel | 2.6.12.1 |
| Linux | Linux Kernel | 2.6.12.2 |
| Linux | Linux Kernel | 2.6.12.3 |
| Linux | Linux Kernel | 2.6.12.4 |
| Linux | Linux Kernel | 2.6.12.5 |
| Linux | Linux Kernel | 2.6.12.6 |
| Linux | Linux Kernel | 2.6.12.12 |
| Linux | Linux Kernel | 2.6.12.22 |
| Linux | Linux Kernel | 2.6.13 |
| Linux | Linux Kernel | 2.6.13.1 |
| Linux | Linux Kernel | 2.6.13.2 |
| Linux | Linux Kernel | 2.6.13.3 |
| Linux | Linux Kernel | 2.6.13.4 |
| Linux | Linux Kernel | 2.6.13.5 |
| Linux | Linux Kernel | 2.6.14 |
| Linux | Linux Kernel | 2.6.14.1 |
| Linux | Linux Kernel | 2.6.14.2 |
| Linux | Linux Kernel | 2.6.14.3 |
| Linux | Linux Kernel | 2.6.14.4 |
| Linux | Linux Kernel | 2.6.14.5 |
| Linux | Linux Kernel | 2.6.14.6 |
| Linux | Linux Kernel | 2.6.14.7 |
Showing 50 of 148 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-2453?
How severe is CVE-2007-2453?
How do I fix CVE-2007-2453?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-2447The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.…
- CVE-2007-2448Subversion 1.4.3 and earlier does not properly implement the…
- CVE-2007-2449Multiple cross-site scripting (XSS) vulnerabilities in certa…
- CVE-2007-2450Multiple cross-site scripting (XSS) vulnerabilities in the (…
- CVE-2007-2451Unspecified vulnerability in drivers/crypto/geode-aes.c in G…
- CVE-2007-2452Heap-based buffer overflow in the visit_old_format function …
- CVE-2007-2454Heap-based buffer overflow in the VGA device in Parallels al…
- CVE-2007-2455Parallels allows local users to cause a denial of service (v…
- CVE-2007-2456Multiple PHP remote file inclusion vulnerabilities in FireFl…
- CVE-2007-2457PHP remote file inclusion vulnerability in resources/include…
- CVE-2007-2458Multiple PHP remote file inclusion vulnerabilities in Pixari…
- CVE-2007-2459Heap-based buffer overflow in the BMP reader (bmp.c) in Imag…
Are you affected by CVE-2007-2453?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
