VDB

CVE-2019-15847

CVE-2019-15847 PUBLISHED

The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.

EPSS 0.54% · 67.9th percentile

Risk Scores

EPSS Score
0.54%
67.9th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSgcc-7-cross17ubuntu1, 0, 8ubuntu2
Ubuntu:16.04:LTSgcc-snapshot20160105-1ubuntu1, 20151030-1ubuntu2, 20151215-0ubuntu1
Ubuntu:22.04:LTSgcc-9-cross-ports0, 24ubuntu1, 24ubuntu1.1
Ubuntu:24.04:LTSgcc-snapshot1:20231130-1ubuntu1, 0, *
Ubuntu:20.04:LTSgcc-10*, *, *
Ubuntu:20.04:LTSgcc-snapshot1:20191201-0ubuntu1, 1:20191008-1ubuntu1, 0
Ubuntu:18.04:LTSgcc-6-cross30ubuntu2, 29ubuntu1, 28ubuntu1
Ubuntu:20.04:LTSgcc-8-cross-ports27ubuntu1, 0, 24ubuntu2
Ubuntu:18.04:LTSgcc-77.2.0-18ubuntu2, 7.3.0-3ubuntu1, 7.3.0-11ubuntu1
Ubuntu:22.04:LTSgcc-snapshot0, 1:20210827-1ubuntu1, *
Ubuntu:18.04:LTSgcc-7-cross-ports6ubuntu1, *, *
Ubuntu:24.04:LTSgcc-9-cross-ports*, 0, 26ubuntu1
Ubuntu:20.04:LTSgcc-8-cross33ubuntu1, 33ubuntu2, 0
Ubuntu:18.04:LTSgcc-snapshot20180107-1ubuntu1, 1:20180322-1ubuntu1, 1:20180425-1ubuntu1
Ubuntu:18.04:LTSgcc-8-cross5ubuntu2, *, 0
Ubuntu:18.04:LTSgcc-8*, *, 0
Ubuntu:18.04:LTSgcc-6-cross-ports28ubuntu2, *, *
Ubuntu:18.04:LTSgcc-66.4.0-11ubuntu1, 6.4.0-16ubuntu1, 6.5.0-2ubuntu1~18.04
Ubuntu:20.04:LTSgcc-9-cross-ports17ubuntu1, 18ubuntu3, *
Ubuntu:18.04:LTSgcc-8-cross-ports6ubuntu3, 4ubuntu1, 3ubuntu1

…and 1 more

Exploit Intelligence

Timeline

  • Sep 2, 2019 CVE Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • May 1, 2022 EPSS Score
  • Jul 3, 2022 EPSS Score
  • Sep 4, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›