CVE-2019-15847 in GNU and OpenSuse Products
Published on September 2, 2019
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.
Products Associated with CVE-2019-15847
stack.watch emails you whenever new vulnerabilities are published in GNU Gcc or OpenSuse Leap. Just hit a watch button to start following.
Exploit Probability
EPSS
0.74%
Percentile
72.63%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.