AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2025-7394.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSUnscoredNo severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSMicrosoft vendor recordModified Feb 17, 2026

Disclosure summary

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL af

Source-reported weakness categories

CWE-200

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

Microsoft Security Updates (CVRF) · 2025-Jul

Open original source · Updated Feb 17, 2026

In the OpenSSL compatibility layer implementation, the function RAND_poll() was not behaving as expected and leading to the potential for predictable values returned from RAND_bytes() after fork() is called. This can lead to weak or predictable random numbers generated in applications that are both using RAND_bytes() and doing fork() operations. This only affects applications explicitly calling RAND_bytes() after fork() and does not affect any internal TLS operations. Although RAND_bytes() documentation in OpenSSL calls out not being safe for use with fork() without first calling RAND_poll(), an additional code change was also made in wolfSSL to make RAND_bytes() behave similar to OpenSSL af

Maximum of vendor-reported product scores; products and fixed builds are associations, not a universal affected-version statement.

VendorProduct / associationVersion / bounds
Microsoft update guidecbl2 mariadb 10.6.21-1 on CBL Mariner 2.0 (MSRC status code 3)
Microsoft update guideazl3 mariadb 10.11.11-1 on Azure Linux 3.0 (MSRC status code 3)

Vendor remediation references

  • CBL-Mariner Releases · product IDs 20085-17086, 19283-17084
  • Vendor guidance · product IDs 20085-17086, 19283-17084

Original records & references

PUBLISHED 2025-09-03T23:46:05-04:00
MODIFIED 2026-02-17T21:19:45-05:00
INGESTED 2026-10-08T12:45:47-04:00