Logo
vulnerabilityCVE-2019-15847
Name
CVE-2019-15847
Source
NVD ( link)Debian ( link)
Description
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
gcc
Exploitable

Vulnerability Ratings#


7.5
CVSSv31
5
CVSSv2

Others affected components#


Name
Project
Project Version
Version
Status
openwrt
master
7
Exploitable
yocto
kirkstone
11.5.0
Not Affected
yocto
master
16.1.0
Not Affected
yocto
scarthgap
13.4.0
Not Affected