LOW · 3.7

CVE-2020-16166

The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is relate...

Vulnerability Description

The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.

CVSS Score

3.7

LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel<= 5.7.11
OpensuseLeap15.1
FedoraprojectFedora31
DebianDebian Linux9.0
CanonicalUbuntu Linux14.04
NetappActive Iq Unified Manager>= 9.5
NetappCloud Volumes Ontap Mediator-
NetappE-Series Santricity Os Controller>= 11.0.0, <= 11.60.3
NetappHci Bootstrap Os-
NetappHci Management Node-
NetappSolidfire-
NetappSteelstore Cloud Integrated Storage-
NetappStoragegrid<= 9.0.4
NetappH410C Firmware-
NetappH410C-
OracleSd-Wan Edge8.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-16166?

CVE-2020-16166 is a vulnerability with a CVSS score of 3.7 (LOW). The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is relate...

How severe is CVE-2020-16166?

CVE-2020-16166 has been rated LOW with a CVSS base score of 3.7/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-16166?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Opensuse Leap, Fedoraproject Fedora, Debian Debian Linux, Canonical Ubuntu Linux.