CVE-2018-1426

IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force ID: 139071.
References
Configurations

Configuration 1


Information

Published : 2018-03-22 12:29

Updated : 2020-08-24 05:37


NVD link : CVE-2018-1426

Mitre link : CVE-2018-1426

Products Affected
No products.
CWE
CWE-335

Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)