4.3

CVE-2020-16166

The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 5.7.11
OpensuseLeap Version15.1
OpensuseLeap Version15.2
FedoraprojectFedora Version31
FedoraprojectFedora Version32
DebianDebian Linux Version9.0
CanonicalUbuntu Linux Version14.04 SwEditionesm
CanonicalUbuntu Linux Version16.04 SwEditionlts
CanonicalUbuntu Linux Version18.04 SwEditionlts
CanonicalUbuntu Linux Version20.04 SwEditionlts
NetappActive Iq Unified Manager SwPlatformvmware_vsphere Version >= 9.5
NetappE-series Santricity Os Controller Version >= 11.0.0 <= 11.60.3
NetappHci Bootstrap Os Version-
NetappSolidfire Version-
NetappStoragegrid Version <= 9.0.4
NetappH410c Firmware Version-
   NetappH410c Version-
OracleSd-wan Edge Version8.2
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 1.85% 0.824
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
CWE-330 Use of Insufficiently Random Values

The product uses insufficiently random numbers or values in a security context that depends on unpredictable numbers.

https://usn.ubuntu.com/4526-1/
Third Party Advisory
https://usn.ubuntu.com/4525-1/
Third Party Advisory
https://arxiv.org/pdf/2012.07432.pdf
Third Party Advisory
Technical Description