In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL after a fork() call without calling RAND_poll(). Now the Hash-DRBG used gets reseeded after detecting running in a new process. If making use of RAND_bytes() and calling fork() we recommend updating to the latest version of wolfSSL. Thanks to Per Allansson from Appgate for the report.
{
"sources": [
{
"url": "https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2025-7394",
"database_specific": {
"status": "Analyzed"
},
"html_url": "https://nvd.nist.gov/vuln/detail/CVE-2025-7394",
"published": "2025-07-18T23:15:23.470Z",
"modified": "2026-06-17T10:04:50.223Z",
"imported": "2026-07-17T22:25:33.208Z",
"id": "CVE-2025-7394"
},
{
"url": "https://api.github.com/advisories/GHSA-jgh6-fqf6-cpj8",
"html_url": "https://github.com/advisories/GHSA-jgh6-fqf6-cpj8",
"published": "2025-07-19T00:32:31Z",
"modified": "2025-12-03T15:30:27Z",
"imported": "2026-07-17T22:25:33.391Z",
"id": "GHSA-jgh6-fqf6-cpj8"
},
{
"url": "https://euvdservices.enisa.europa.eu/api/enisaid?id=EUVD-2025-21938",
"html_url": "https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-21938",
"published": "2025-07-18T22:34:23Z",
"modified": "2025-07-21T15:00:21Z",
"imported": "2026-07-17T22:25:42.409Z",
"id": "EUVD-2025-21938"
}
],
"license": "CC-BY-4.0"
}