CVE-2025-7394Disclosure(wolfssl / wolfssl)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL after a fork() call without calling RAND_poll(). Now the Hash-DRBG used gets reseeded after detecting running in a new process. If making use of RAND_bytes() and calling fork() we recommend updating to the latest version of wolfSSL. Thanks to Per Allansson from Appgate for the report.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-338

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wolfssl

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
wolfssl

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-01-29: 1Technical Details · 2026-01-29: 101-29
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • wolfSSL Japan - 自社開発の耐量子暗号を含む暗号およびSSL/TLSライブラリを提供@wolfSSL_Japan
    Disclosure

    脆弱性の開示:wolfSSLにおいて予測可能な乱数値を使用するおそれ (CVE-2025-7394): 影響を受けるユーザ v5.8.2より前のwolfSSLでOpenSSL互換レイヤーを用いて、RAND_byte…続きを読む http://dlvr.it/TQcyk5 https://t.co/zMrCMQvDtz

    Post summary

    A disclosure of CVE-2025‑7394, a predictable random number problem in wolfSSL versions before 5.8.2 affecting users with the OpenSSL compatibility layer.

    00000166
    1.9K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwolfsslwolfssl---

Explore more