2.1
CVSSv2

CVE-2017-11671

Published: 26/07/2017 Updated: 12/04/2018
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 4 | Impact Score: 1.4 | Exploitability Score: 2.5
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Under certain circumstances, the ix86_expand_builtin function in i386.c in GNU Compiler Collection (GCC) version 4.6, 4.7, 4.8, 4.9, 5 prior to 5.5, and 6 prior to 6.4 will generate instruction sequences that clobber the status flag of the RDRAND and RDSEED intrinsics before it can be read, potentially causing failures of these instructions to go unreported. This could potentially lead to less randomness in random number generation.

Vulnerable Product Search on Vulmon Subscribe to Product

gnu gcc 6.2

gnu gcc 6.1

gnu gcc 4.9

gnu gcc 4.8

gnu gcc 6.0

gnu gcc 5.4

gnu gcc 4.7

gnu gcc 4.6

gnu gcc 5.3

gnu gcc 5.2

gnu gcc 6.3

gnu gcc 5.1

gnu gcc 5.0

Vendor Advisories

Synopsis Low: gcc security, bug fix, and enhancement update Type/Severity Security Advisory: Low Topic An update for gcc is now available for Red Hat Enterprise Linux 7Red Hat Product Security has rated this update as having a security impact of Low A Common Vulnerability Scoring System (CVSS) base score, ...