VYPR
Critical severity9.8NVD Advisory· Published Jul 18, 2025· Updated Jun 17, 2026

CVE-2025-7394

CVE-2025-7394

Description

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL after a fork() call without calling RAND_poll(). Now the Hash-DRBG used gets reseeded after detecting running in a new process. If making use of RAND_bytes() and calling fork() we recommend updating to the latest version of wolfSSL. Thanks to Per Allansson from Appgate for the report.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • WolfSSL/Wolfssl3 versions
    cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:wolfssl:wolfssl:*:*:*:*:*:*:*:*range: >=3.15.0,<=5.8.0
    • (no CPE)
    • (no CPE)range: 3.15.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.