CVE-2025-7394CRITICAL 9.8EPSS p30.3%
CVE-2025-7394CVE-2025-7394
Description
In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL after a fork() call without calling RAND_poll(). Now the Hash-DRBG used gets reseeded after detecting running in a new process. If making use of RAND_bytes() and calling fork() we recommend updating to the latest version of wolfSSL. Thanks to Per Allansson from Appgate for the report.
Scoring
| CVSS 3.1 | 9.8 (CRITICAL) |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.39% probability of exploitation · percentile 30.3% · 2026-06-19T12:03:05Z |
| Published | 2025-07-18 |
| Last modified | 2025-12-03 |
Underlying weaknesses· 2
References
2
| Type | Target | Confidence | Tier |
|---|---|---|---|
| Weakness | Exposure of Sensitive Information to an Unauthorized Actorcwe-200 | 0% | live |
| Weakness | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)cwe-338 | 0% | live |
Related by meaning· 6
Nearest entities by semantic similarity across the cs-graph corpus.