CVE-2025-0577
Last modified
CVE-2025-0577 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-0577?
How severe is CVE-2025-0577?
How do I fix CVE-2025-0577?
Are you affected by CVE-2025-0577?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
