folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00.
"2026-04-11T08:05:27Z"
[
{
"id": "CVE-2018-6337-26c63d9e",
"target": {
"file": "folly/Random.cpp",
"function": "BufferedRandomDevice::BufferedRandomDevice"
},
"deprecated": false,
"digest": {
"function_hash": "284036517926769522446303472293932871264",
"length": 167.0
},
"signature_type": "Function",
"source": "https://github.com/facebook/folly/commit/8e927ee48b114c8a2f90d0cbd5ac753795a6761f",
"signature_version": "v1"
},
{
"id": "CVE-2018-6337-8d3baadc",
"target": {
"file": "folly/Random.cpp"
},
"deprecated": false,
"digest": {
"line_hashes": [
"177920330538644327192225453200305065783",
"59911639472083442187456794245162808999",
"65172725879389982502094016348740295630",
"17990193584615700481737216549983378364",
"209095503057375019683009475243350527423",
"296410358608657755139750410745821126905",
"6183588544461503112388437451448205621",
"235905810367433042539041352614098937893",
"13633877825802383340203296441577109962",
"34706653758255140459594012130281298023",
"323743310232915005554048423781952476189",
"106311966400258842219023665560878942543",
"230258836968319331137014607436219812468",
"20826410772747688904839131406196838226",
"117656596208525043926138988524382117691"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/facebook/folly/commit/8e927ee48b114c8a2f90d0cbd5ac753795a6761f",
"signature_version": "v1"
},
{
"id": "CVE-2018-6337-9642f365",
"target": {
"file": "hphp/runtime/version.h"
},
"deprecated": false,
"digest": {
"line_hashes": [
"32876589609925362676926719200585395072",
"109574309600017076406065776388583700439",
"281574740350394436842520560909858709910",
"140335216194151808759673220052749435881"
],
"threshold": 0.9
},
"signature_type": "Line",
"source": "https://github.com/facebook/hhvm/commit/cea63133cb066ebff74f9fc42789fa2017beab55",
"signature_version": "v1"
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-6337.json"