CVE-2007-4311

Linux kernel <2.4.35 - Info Disclosure

Title source: llm

Description

The xfer_secondary_pool function in drivers/char/random.c in the Linux kernel 2.4 before 2.4.35 performs reseed operations on only the first few bytes of a buffer, which might make it easier for attackers to predict the output of the random number generator, related to incorrect use of the sizeof operator.

Scores

EPSS 0.0065
EPSS Percentile 70.4%

Classification

CWE
CWE-310
Status draft

Affected Products (1)

linux/linux_kernel < 2.4.34

Timeline

Published Aug 13, 2007
Tracked Since Feb 18, 2026