CVE-2017-11671
Last modified
CVE-2017-11671 is a vulnerability of currently unknown severity. Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gnu | Gcc | 4.6 |
| Gnu | Gcc | 4.7 |
| Gnu | Gcc | 4.8 |
| Gnu | Gcc | 4.9 |
| Gnu | Gcc | 5.0 |
| Gnu | Gcc | 5.1 |
| Gnu | Gcc | 5.2 |
| Gnu | Gcc | 5.3 |
| Gnu | Gcc | 5.4 |
| Gnu | Gcc | 6.0 |
| Gnu | Gcc | 6.1 |
| Gnu | Gcc | 6.2 |
| Gnu | Gcc | 6.3 |
References
- http://openwall.com/lists/oss-security/2017/07/27/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/100018Third Party Advisory, VDB Entry
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=80180Issue Tracking, Vendor Advisory
- http://openwall.com/lists/oss-security/2017/07/27/2Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/100018Third Party Advisory, VDB Entry
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=80180Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-11671?
How severe is CVE-2017-11671?
How do I fix CVE-2017-11671?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-11665The ff_amf_get_field_value function in libavformat/rtmppkt.c…
- CVE-2017-11666Cross-site scripting (XSS) vulnerability in js/ViewerPanel.j…
- CVE-2017-11667OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles ses…
- CVE-2017-11668An out-of-bounds read flaw related to the assess_packet func…
- CVE-2017-11669An out-of-bounds read flaw related to the assess_packet func…
- CVE-2017-11670A length validation (leading to out-of-bounds read and write…
- CVE-2017-11672The OPC Foundation Local Discovery Server (LDS) before 1.03.…
- CVE-2017-11673Reporter.exe in Acunetix 8 allows remote attackers to execut…
- CVE-2017-11674Reporter.exe in Acunetix 8 allows remote attackers to cause …
- CVE-2017-11675The traverseStrictSanitize function in admin_dir/includes/cl…
- CVE-2017-11677Cross-site scripting (XSS) vulnerability in Hashtopus 1.5g a…
- CVE-2017-11678SQL injection vulnerability in Hashtopus 1.5g allows remote …
Are you affected by CVE-2017-11671?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
