CVE-2018-6337

HIGH

Facebook Folly 2017.12.11.00-2018.08.09.00 and HHVM 3.26-3.26.3 - Weak Randomness via Forked Process Buffer Reuse

Title source: llm
STIX 2.1

Description

folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00.

References (3)

Core 3

Scores

CVSS v3 7.5
EPSS 0.0178
EPSS Percentile 75.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-119 CWE-212
Status published
Products (2)
facebook/folly 2017.12.11.00 - 2018.08.09.00
facebook/hhvm 3.26 - 3.26.3
Published Dec 31, 2018
Tracked Since Feb 18, 2026