Impact
The Linux kernel’s qcom-rng random number generator mistakenly rejects zero, making the stream detectable as non‑random. This flaw does not leak secrets directly, but it introduces a statistical bias that could allow an adversary to distinguish the output from a true random source and therefore infer properties of the RNG state or subsequent data derived from it.
Affected Systems
This issue affects the generic Linux kernel implementation, specifically the qcom-rng module. No explicit version numbers are provided, but the vulnerability was fixed in a recent kernel commit. The affected vendor/product identifiers are Linux:Linux.
Risk and Exploitability
Because the flaw only impacts the statistical distribution of generated numbers, the direct exploitation surface is limited. No exploit probability (EPSS) is reported and the vulnerability is not listed in the CISA KEV catalog. The CVSS score is also absent from the data, so the exact severity cannot be quantified. The likely attack vector would involve an attacker with a need to identify subtle RNG weaknesses, for example in cryptographic protocols that rely on perfect randomness, though practical impact is uncertain without further context.
OpenCVE Enrichment
Debian DSA