Back

CRITICAL

PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm

Published Oct 27, 2021

Description

PolarSSL versions prior to v1.1 use the HAVEGE random number generation algorithm. At its heart, this uses timing information based on the processor's high resolution timer (the RDTSC instruction). This instruction can be virtualized, and some virtual machine hosts have chosen to disable this instruction, returning 0s or predictable results.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 27, 2021
Updated Aug 7, 2024
Reserved Nov 29, 2011
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date n/a