Bug 2509968 (CVE-2026-18536)
| Summary: | CVE-2026-18536 Data-Entropy: Data-Entropy: Predictable random numbers due to unencrypted remote entropy sources | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | Keywords: | Security |
| Target Milestone: | --- | ||
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in Data-Entropy. This component reads remote entropy (randomness) sources over unencrypted HTTP. An on-path attacker, such as one on an open Wi-Fi network or a compromised internet service provider (ISP), can intercept and alter the responses from these sources. This allows the attacker to control the random bytes generated by the application, leading to predictable random numbers. Such a compromise of cryptographic randomness can have significant security implications, potentially enabling further attacks.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2514598, 2514600 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-08-01 11:01:07 UTC
|