Sploitus

CVE-2025-7394

No indexed exploits for CVE-2025-7394 yet

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL after a fork() call without calling RAND_poll(). Now the Hash-DRBG used gets reseeded after detecting running in a new process. If making use of RAND_bytes() and calling fork() we recommend updating to the latest version of wolfSSL. Thanks to Per Allansson from Appgate for the report.

Affected products
Debian, Wolfssl
Wolfssl
≤ 5.8.0
Fix
Available
CVSS 3.1
9.8 CRITICAL
EPSS
0.4% (31th percentile)
Weakness
CWE-338, CWE-200
NVD status
Analyzed
Published
2025-07-18
CVE-2025-7394 at NVD
Authoritative description, scoring and affected products

No indexed exploits for CVE-2025-7394 yet

Our index is partial: it proves presence, never absence

No exploit for CVE-2025-7394 has been indexed yet. Our index is built from live traffic and upstream syncs, so this page can only say what it knows — not that no exploit exists.