CVE-2019-1549: Fork Protection

Published Sep 10, 2019
·
Updated

Last updated 25 August 2025

Other sources

OpenSSL 1.1.1 introduced a rewritten random number generator (RNG). Th ...

Debian

Affected Software

11 affected componentsFixes available
redhat/jbcs-httpd24-apr<0:1.6.3-86.jbcs.el6
0:1.6.3-86.jbcs.el6
redhat/jbcs-httpd24-brotli<0:1.0.6-21.jbcs.el6
0:1.0.6-21.jbcs.el6
redhat/jbcs-httpd24-httpd<0:2.4.37-52.jbcs.el6
0:2.4.37-52.jbcs.el6
redhat/jbcs-httpd24-openssl<1:1.1.1c-16.jbcs.el6
1:1.1.1c-16.jbcs.el6
redhat/jbcs-httpd24-apr<0:1.6.3-86.jbcs.el7
0:1.6.3-86.jbcs.el7
redhat/jbcs-httpd24-brotli<0:1.0.6-21.jbcs.el7
0:1.0.6-21.jbcs.el7
redhat/jbcs-httpd24-httpd<0:2.4.37-52.jbcs.el7
0:2.4.37-52.jbcs.el7
redhat/jbcs-httpd24-openssl<1:1.1.1c-16.jbcs.el7
1:1.1.1c-16.jbcs.el7
redhat/openssl<1:1.1.1c-15.el8
1:1.1.1c-15.el8
OpenSSL OpenSSL>=1.1.1<=1.1.1c
debian/openssl
1.1.1w-0+deb11u11.1.1w-0+deb11u83.0.20-1~deb12u13.0.20-1~deb12u23.5.6-1~deb13u13.5.6-1~deb13u23.6.3-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/jbcs-httpd24-apr to a version that resolves this vulnerability.

    Fixed in 0:1.6.3-86.jbcs.el6
  2. Upgrade

    Upgrade redhat/jbcs-httpd24-brotli to a version that resolves this vulnerability.

    Fixed in 0:1.0.6-21.jbcs.el6
  3. Upgrade

    Upgrade redhat/jbcs-httpd24-httpd to a version that resolves this vulnerability.

    Fixed in 0:2.4.37-52.jbcs.el6
  4. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl to a version that resolves this vulnerability.

    Fixed in 1:1.1.1c-16.jbcs.el6
  5. Upgrade

    Upgrade redhat/jbcs-httpd24-apr to a version that resolves this vulnerability.

    Fixed in 0:1.6.3-86.jbcs.el7
  6. Upgrade

    Upgrade redhat/jbcs-httpd24-brotli to a version that resolves this vulnerability.

    Fixed in 0:1.0.6-21.jbcs.el7
  7. Upgrade

    Upgrade redhat/jbcs-httpd24-httpd to a version that resolves this vulnerability.

    Fixed in 0:2.4.37-52.jbcs.el7
  8. Upgrade

    Upgrade redhat/jbcs-httpd24-openssl to a version that resolves this vulnerability.

    Fixed in 1:1.1.1c-16.jbcs.el7
  9. Upgrade

    Upgrade redhat/openssl to a version that resolves this vulnerability.

    Fixed in 1:1.1.1c-15.el8
  10. Upgrade

    Upgrade debian/openssl to a version that resolves this vulnerability.

    Fixed in 1.1.1w-0+deb11u1Fixed in 1.1.1w-0+deb11u8Fixed in 3.0.20-1~deb12u1Fixed in 3.0.20-1~deb12u2Fixed in 3.5.6-1~deb13u1Fixed in 3.5.6-1~deb13u2Fixed in 3.6.3-1
  11. Upgrade

    Upgrade OpenSSL to a version that resolves this vulnerability.

    Fixed in 1.1.1d
  12. Configuration

    Call OPENSSL_init_crypto() explicitly with OPENSSL_INIT_ATFORK (e.g., OPENSSL_init_crypto(..., OPENSSL_INIT_ATFORK)) so the fork protection is enabled and parent/child processes do not share the same RNG state.

    OpenSSL OPENSSL_init_crypto() initialization flags (OPENSSL_INIT_ATFORK) = Use OPENSSL_INIT_ATFORK
  13. Compensating control

    If OPENSSL_INIT_ATFORK cannot be used, apply the documented partial mitigation of mixing the output from a high precision timer into the RNG state to significantly reduce the likelihood that a parent and child process share the same RNG state.

Event History

Sep 10, 2019
CVE Published
12:00 AM
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
DescriptionWeakness
Sep 13, 2019
Data Sourced
via Red Hat·05:08 PM
DescriptionSeverityAffected Software
Feb 23, 2026
Data Sourced
via Ubuntu·02:43 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Launchpad·02:43 PM
Description
Jun 17, 2026
Data Sourced
via Debian·01:27 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Frequently Asked Questions

1

What is CVE-2019-1549?

CVE-2019-1549 is a vulnerability in OpenSSL 1.1.1 that affects the random number generator (RNG).

2

What is the severity of CVE-2019-1549?

CVE-2019-1549 has a severity rating of 5.3, which is considered medium.

3

How does CVE-2019-1549 affect OpenSSL?

CVE-2019-1549 affects OpenSSL 1.1.1 by enabling the parent and child processes to share the same RNG state during a fork() system call, which poses a security risk.

4

What is the remediation for CVE-2019-1549?

To remediate CVE-2019-1549, update OpenSSL to version 1.1.1c or higher.

5

Where can I find more information about CVE-2019-1549?

You can find more information about CVE-2019-1549 in the OpenSSL security advisory and related references.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203