{"id":"CVE-2018-6337","details":"folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM 3.26 prior to 3.26.3 and the folly library between v2017.12.11.00 and v2018.08.09.00.","modified":"2026-05-18T17:45:03.618180Z","published":"2018-12-31T22:29:00.247Z","references":[{"type":"ADVISORY","url":"https://hhvm.com/blog/2018/05/24/hhvm-3.26.3.html"},{"type":"FIX","url":"https://github.com/facebook/folly/commit/8e927ee48b114c8a2f90d0cbd5ac753795a6761f"},{"type":"FIX","url":"https://github.com/facebook/hhvm/commit/e2d10a1e32d01f71aaadd81169bcb9ae86c5d6b8"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/facebook/folly","events":[{"introduced":"712b8b8de747960ceeceedfd3a18ee23a0c03a80"},{"last_affected":"c4fca6d0852bc68b1387c755be7a22710af70cb3"}],"database_specific":{"cpe":"cpe:2.3:a:facebook:folly:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"2017.12.11.00"},{"last_affected":"2018.08.09.00"}],"source":"CPE_FIELD"}}],"versions":["v2018.08.09.00","v2018.08.06.00","v2018.07.30.00","v2018.07.23.00","v2018.07.16.00","v2018.07.09.00","v2018.07.02.00","v2018.06.25.00","v2018.06.18.00","v2018.06.11.00","v2018.06.04.00","v2018.05.28.00","v2018.05.21.00","v2018.05.14.00","v2018.05.07.00","v2018.04.30.00","v2018.04.23.00","v2018.04.16.00","v2018.04.09.00","v2018.04.02.00","v2018.03.26.00","v2018.03.19.00","v2018.03.12.00","v2018.03.05.00","v2018.02.26.00","v2018.02.19.00","v2018.02.12.00","v2018.02.05.00","v2018.01.29.00","v2018.01.22.00","v2018.01.15.00","v2018.01.08.00","v2018.01.01.00","v2017.12.25.00","v2017.12.18.00","v2017.12.11.00"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-6337.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/facebook/hhvm","events":[{"introduced":"a20c2a7761b782faf1635dfe2f1f8f0df438196d"},{"fixed":"cea63133cb066ebff74f9fc42789fa2017beab55"}],"database_specific":{"cpe":"cpe:2.3:a:facebook:hhvm:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.26"},{"fixed":"3.26.3"}],"source":"CPE_FIELD"}}],"versions":["HHVM-3.26.2","HHVM-3.26.1","HHVM-3.26.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-6337.json","vanir_signatures_modified":"2026-05-18T17:45:03Z","vanir_signatures":[{"digest":{"line_hashes":["32876589609925362676926719200585395072","109574309600017076406065776388583700439","281574740350394436842520560909858709910","140335216194151808759673220052749435881"],"threshold":0.9},"id":"CVE-2018-6337-9642f365","signature_type":"Line","signature_version":"v1","source":"https://github.com/facebook/hhvm/commit/cea63133cb066ebff74f9fc42789fa2017beab55","target":{"file":"hphp/runtime/version.h"},"deprecated":false}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}