CVE-2025-0577

MEDIUM

glibc - Insufficient Entropy

Title source: llm

Description

An insufficient entropy vulnerability was found in glibc. The getrandom and arc4random family of functions may return predictable randomness if these functions are called again after the fork, which happens concurrently with a call to any of these functions.

Scores

CVSS v3 4.8
EPSS 0.0009
EPSS Percentile 26.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Classification

CWE
CWE-331
Status draft

Timeline

Published Feb 18, 2026
Tracked Since Feb 19, 2026