tgt (aka Linux target framework) before 1.0.93 attempts to achieve
entropy by calling rand without srand. The PRNG seed is always 1, and
thus the sequence of challenges is always identical. (CVE-2024-45751)
- https://bugs.mageia.org/show_bug.cgi?id=33545
- https://www.openwall.com/lists/oss-security/2024/09/07/2
- https://www.cve.org/CVERecord?id=CVE-2024-45751
- 9/core/tgt-1.0.85-1.1.mga9
Get the latest Linux and open source security news straight to your inbox.