
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-16166 affects the Linux kernel through version 5.7.11. The vulnerability allows remote attackers to make observations that help obtain sensitive information about the internal state of the network RNG (Random Number Generator). This vulnerability is related to code in drivers/char/random.c and kernel/time/timer.c (NVD).
The vulnerability stems from the predictability of the random number generator used by the network stack, which might not be re-seeded for long periods of time. This affects operations like client port number allocations, making them more predictable. The issue was addressed by replacing the LFSR with a homebrew cryptographic PRNG based on the SipHash round function, seeded with 128 bits of strong random key (Kernel Commit).
The vulnerability makes it easier for remote attackers to carry out network-based attacks such as DNS cache poisoning or device tracking by predicting network RNG outputs (Debian).
This vulnerability is remotely exploitable without authentication. It has a CVSS v3.1 base score of 3.7 (LOW) with vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N (NetApp Advisory).
The vulnerability was fixed in Linux kernel versions after 5.7.11. The fix involves implementing a new random number generation mechanism using SipHash for better unpredictability. Users should upgrade to patched kernel versions (Fedora Update).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."