CVE-2017-11671

Source
https://cve.org/CVERecord?id=CVE-2017-11671
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11671.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-11671
Downstream
Related
Published
2017-07-26T21:29:00.207Z
Modified
2026-02-13T08:10:55.060630Z
Severity
  • 4.0 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N CVSS Calculator
Summary
[none]
Details

Under certain circumstances, the ix86expandbuiltin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 before 5.5, and 6 before 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

References

Affected packages

Git / github.com/gcc-mirror/gcc

Affected ranges

Type
GIT
Repo
https://github.com/gcc-mirror/gcc
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other
basepoints/gcc-0
misc/cutover-cvs2svn
misc/cutover-egcs-0
misc/cutover-egcs-1
releases/gcc-4.*
releases/gcc-4.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-11671.json"