OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). This was intended to include protection in the event of a fork() system call in order to ensure that the parent and child processes did not share the same RNG state. However this protection was not being used in the default case. A partial mitigation for this issue is that the output from a high precision timer is mixed into the RNG state so the likelihood of a parent and child process sharing state is significantly reduced. If an application already calls OPENSSL_init_crypto() explicitly using OPENSSL_INIT_ATFORK then this problem does not occur at all. Fixed in OpenSSL 1.1.1d (Affected 1.1.1-1.1.1c).
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade openssl1.1-compatUpgrade opensslUpgrade openssl3 | Dec 27, 2019 | Sep 10, 2019 |
| Amazon Linux Ami 2 | — | Upgrade openssl11-libsUpgrade openssl11-staticUpgrade openssl11Upgrade openssl11-debuginfoUpgrade openssl11-devel | Jul 21, 2020 | Sep 10, 2019 |
| Centos_linux | — | Upgrade openssl-debuginfoUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-perlUpgrade openssl-libs-debuginfoUpgrade opensslUpgrade openssl-debugsource | Apr 29, 2020 | Sep 10, 2019 |
| Debian | — | Upgrade openssl | Jul 30, 2024 | Sep 10, 2019 |
| Freebsd | — | Upgrade opensslUpgrade openssl111 | Sep 11, 2019 | Sep 11, 2019 |
| Http Openssl | — | Upgrade to the latest version of OpenSSL | Sep 12, 2019 | Sep 10, 2019 |
| Huawei Euleros 2_0_sp8 | — | Upgrade openssl-libsUpgrade openssl-develUpgrade opensslUpgrade openssl-perl | Nov 19, 2019 | Sep 10, 2019 |
| Oracle Solaris | — | Upgrade library/security/openssl to version 1.0.2.20-11.4.16.0.1.1.0 on Solaris 11.4Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-11.4.16.0.1.1.0 on Solaris 11.4Upgrade library/security/openssl to version 1.0.2.26-0.175.3.36.0.27.0 on Solaris 11.3Upgrade library/security/openssl/openssl-fips-140 to version 2.0.15-0.175.3.36.0.27.0 on Solaris 11.3 | Dec 18, 2019 | Sep 10, 2019 |
| Oracle_linux | — | Upgrade opensslUpgrade openssl-develUpgrade openssl-libsUpgrade openssl-perl | Jul 22, 2024 | Sep 10, 2019 |
| Redhat Openshift | — | Upgrade redhat-coreos | Dec 29, 2020 | Sep 10, 2019 |
| Redhat_linux | — | Upgrade openssl-debugsourceUpgrade opensslUpgrade openssl-perlUpgrade openssl-debuginfoUpgrade openssl-libsUpgrade openssl-develUpgrade openssl-libs-debuginfo | Apr 29, 2020 | Sep 10, 2019 |
| Suse | — | Upgrade libopenssl-1_1-devel-32bitUpgrade libopenssl1_1-32bitUpgrade openssl-1_1Upgrade libopenssl-1_1-develUpgrade libopenssl1_1-hmacUpgrade libopenssl1_1Upgrade libopenssl1_1-hmac-32bit | Jan 16, 2020 | Sep 10, 2019 |
| Ubuntu | — | Upgrade libssl1.1 | May 29, 2020 | Sep 10, 2019 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Sep 10, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub