gcc: POWER9 "DARN" RNG intrinsic produces repeated output
Published Sep 2, 2019
7.5
HIGHCVSS 3.1
EPSS 3.18%
Description
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.
Affected products
No data.
No data.
Red Hat Enterprise Linux 8
gcc-0:8.3.1-5.el8
Fixed · RHSA-2020:1864
Red Hat Enterprise Linux 8
gcc-0:8.3.1-5.el8
Fixed · RHSA-2020:1864
Red Hat Software Collections for Red Hat Enterprise Linux 6
devtoolset-8-gcc-0:8.3.1-3.2.el6
Fixed · RHSA-2020:0924
Red Hat Software Collections for Red Hat Enterprise Linux 7
devtoolset-8-gcc-0:8.3.1-3.2.el7
Fixed · RHSA-2020:0924
Red Hat Software Collections for Red Hat Enterprise Linux 7
devtoolset-9-gcc-0:9.3.1-2.el7
Fixed · RHSA-2020:2274
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS
devtoolset-8-gcc-0:8.3.1-3.2.el7
Fixed · RHSA-2020:0924
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
devtoolset-8-gcc-0:8.3.1-3.2.el7
Fixed · RHSA-2020:0924
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS
devtoolset-9-gcc-0:9.3.1-2.el7
Fixed · RHSA-2020:2274
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
devtoolset-8-gcc-0:8.3.1-3.2.el7
Fixed · RHSA-2020:0924
Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS
devtoolset-9-gcc-0:9.3.1-2.el7
Fixed · RHSA-2020:2274
Red Hat Enterprise Linux 5
gcc
Not affected
Red Hat Enterprise Linux 6
gcc
Not affected
Red Hat Enterprise Linux 7
gcc
Not affected
Red Hat Enterprise Linux 8
mingw-gcc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | gcc-0:8.3.1-5.el8 | Fixed | RHSA-2020:1864 |
| Red Hat Enterprise Linux 8 | gcc-0:8.3.1-5.el8 | Fixed | RHSA-2020:1864 |
| Red Hat Software Collections for Red Hat Enterprise Linux 6 | devtoolset-8-gcc-0:8.3.1-3.2.el6 | Fixed | RHSA-2020:0924 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | devtoolset-8-gcc-0:8.3.1-3.2.el7 | Fixed | RHSA-2020:0924 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7 | devtoolset-9-gcc-0:9.3.1-2.el7 | Fixed | RHSA-2020:2274 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS | devtoolset-8-gcc-0:8.3.1-3.2.el7 | Fixed | RHSA-2020:0924 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | devtoolset-8-gcc-0:8.3.1-3.2.el7 | Fixed | RHSA-2020:0924 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS | devtoolset-9-gcc-0:9.3.1-2.el7 | Fixed | RHSA-2020:2274 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | devtoolset-8-gcc-0:8.3.1-3.2.el7 | Fixed | RHSA-2020:0924 |
| Red Hat Software Collections for Red Hat Enterprise Linux 7.7 EUS | devtoolset-9-gcc-0:9.3.1-2.el7 | Fixed | RHSA-2020:2274 |
| Red Hat Enterprise Linux 5 | gcc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | gcc | Not affected | n/a |
| Red Hat Enterprise Linux 7 | gcc | Not affected | n/a |
| Red Hat Enterprise Linux 8 | mingw-gcc | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
As per upstream DARN (or power9) is not supported in GCC 6 or older, therefore versions of gcc shipped with Red Hat Enterprise Linux 5, 6 and 7 are not affected by this flaw.
References (8)
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2019-15847 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1755523 Issue Tracking
- https://gcc.gnu.org/bugzilla/show_bug.cgi?id=91481 x_refsource_MISCIssue TrackingVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2019-15847
- https://www.cve.org/CVERecord?id=CVE-2019-15847
| Link | Providers | Tags |
|---|---|---|
| http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00056.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2019-10/msg00057.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00058.html | vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2019-15847 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1755523 | Issue Tracking | |
| https://gcc.gnu.org/bugzilla/show_bug.cgi?id=91481 | x_refsource_MISCIssue TrackingVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2019-15847 | ||
| https://www.cve.org/CVERecord?id=CVE-2019-15847 |
Change history (0)
No recorded changes yet.