
16 Dec
2020
16 Dec
'20
11:41 a.m.
From: Matthias Brugger mbrugger@suse.com
For now bootp and uuid code use a weak seed for generating random data. U-Boot as support for RNG devices now, so we should change to code to use them if they are present. This will help mitigate issues like seen in CVE-2019-11690.
Matthias Brugger (2): lib: uuid: use RNG device if present net: Use NDRNG device in srand_mac()
lib/uuid.c | 20 +++++++++++++++++--- net/net_rand.h | 18 +++++++++++++++++- 2 files changed, 34 insertions(+), 4 deletions(-)
--
2.29.2