CVE detail
CVE-2019-15847 — CVE-2019-15847
Published 2019-09-02 · Modified 2026-06-17 · Vendor gnu · Product gcc · Source nvd
HIGH
severity
CVSS-derived band
0.0318
EPSS probability
exploitation probability, 30d
87.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
The POWER9 backend in GNU Compiler Collection (GCC) before version 10 could optimize multiple calls of the __builtin_darn intrinsic into a single call, thus reducing the entropy of the random number generator. This occurred because a volatile operation was not specified. For example, within a single execution of a program, the output of every __builtin_darn() call may be the same.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References