cbcvebase.
CVE-2020-16166
published 2020-07-30

CVE-2020-16166: The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network…

PriorityP422low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
5.27%
91.6th percentile
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.

Affected

24 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 5.7.17-1 (bookworm)linux 5.7.17-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel<= 5.7.11
linuxlinux_kernel>= 0 < 5.7.17-15.7.17-1
linuxlinux_kernel>= 0 < 5.7.17-15.7.17-1
linuxlinux_kernel>= 0 < 5.7.17-15.7.17-1
linuxlinux_kernel>= 0 < 5.7.17-15.7.17-1
linuxlinux_kernel>= 0 < 4.15.0-118.1194.15.0-118.119
linuxlinux_kernel>= 0 < 5.4.0-48.525.4.0-48.52
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccm1_kernel_5.4.91-3_on_cbl_mariner_1.0
netappactive_iq_unified_manager>= 9.5
netappe-series_santricity_os_controller11.0.0 – 11.60.3
netappstoragegrid<= 9.0.4
opensuseleap
opensuseleap
oraclesd-wan_edge

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian3.7LOW
vendor_msrc3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.