CVE-2019-15847
Summary
| CVE | CVE-2019-15847 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-09-02 23:15:00 UTC |
| Updated | 2020-09-17 13:38:00 UTC |
| Description | The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same. |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|
| Application |
Gnu |
Gcc |
All |
All |
All |
All |
| Application |
Gnu |
Gcc |
All |
All |
All |
All |
| Operating System |
Opensuse |
Leap |
15.0 |
All |
All |
All |
| Operating System |
Opensuse |
Leap |
15.1 |
All |
All |
All |
| Operating System |
Opensuse |
Leap |
15.0 |
All |
All |
All |
| Operating System |
Opensuse |
Leap |
15.1 |
All |
All |
All |
References
| Reference | Source | Link | Tags |
|---|
| [security-announce] openSUSE-SU-2019:2365-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| [security-announce] openSUSE-SU-2020:0716-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| 91481 – (CVE-2019-15847) POWER9 "DARN" RNG intrinsic produces repeated output (CVE-2019-15847) |
MISC |
gcc.gnu.org |
Issue Tracking, Vendor Advisory |
| [security-announce] openSUSE-SU-2019:2364-1: moderate: Security update f |
SUSE |
lists.opensuse.org |
Mailing List, Third Party Advisory |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 755898 SUSE Enterprise Linux Security Update for gcc7 (SUSE-SU-2023:3662-1)
- 900124 CBL-Mariner Linux Security Update for gcc 9.1.0
- 903131 Common Base Linux Mariner (CBL-Mariner) Security Update for gcc (1829)
- 905989 Common Base Linux Mariner (CBL-Mariner) Security Update for gcc (1829-1)