CVE-2007-2453

Linux kernel <2.6.20.13, 2.6.21.x <2.6.21.4 - Info Disclosure

Title source: llm
STIX 2.1

Description

The random number feature in Linux kernel 2.6 before 2.6.20.13, and 2.6.21.x before 2.6.21.4, (1) does not properly seed pools when there is no entropy, or (2) uses an incorrect cast when extracting entropy, which might cause the random number generator to provide the same values after reboots on systems without an entropy source.

References (27)

Core 27
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-470-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/24390
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:171
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34781
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:216
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-489-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018248
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26664
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_51_kernel.html
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/2105
Vendor Advisory vendor-advisory x_refsource_suse
http://www.novell.com/linux/security/advisories/2007_43_kernel.html
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1356
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26620
Vendor Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDKSA-2007:196
Patch mailing-list x_refsource_mlist
http://marc.info/?l=linux-kernel&m=118128622431272&w=2
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25961
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/37114
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25596
Vendor Advisory vendor-advisory x_refsource_redhat
https://rhn.redhat.com/errata/RHSA-2007-0376.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-486-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26450
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25700
Patch mailing-list x_refsource_mlist
http://marc.info/?l=linux-kernel&m=118128610219959&w=2
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9960
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26139
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26133

Scores

EPSS 0.0037
EPSS Percentile 29.8%

Details

Status published
Products (12)
linux/linux_kernel 2.6.0 (12 CPE variants)
linux/linux_kernel 2.6.1 (4 CPE variants)
linux/linux_kernel 2.6.2 (4 CPE variants)
linux/linux_kernel 2.6.3 (5 CPE variants)
linux/linux_kernel 2.6.4 (4 CPE variants)
linux/linux_kernel 2.6.5 (4 CPE variants)
linux/linux_kernel 2.6.6 (4 CPE variants)
linux/linux_kernel 2.6.7 (4 CPE variants)
linux/linux_kernel 2.6.8 (5 CPE variants)
linux/linux_kernel 2.6.8.1
... and 2 more
Published Jun 11, 2007
Tracked Since Feb 18, 2026