CVE-2020-16166: Canonical Ubuntu Linux
Low severity, CVSS 3.7. EPSS: 5.3% chance of exploitation in the next 30 days.
The Linux kernel through 5.7.11 allows remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG, aka CID-f227e3ec3b5c. This is related to drivers/char/random.c and kernel/time/timer.c.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only; version 20.04 only
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 31 only; version 32 only
- Linux Linux Kernel: up to and including 5.7.11
- Netapp Active Iq Unified Manager: from 9.5
- Netapp Cloud Volumes Ontap Mediator: affected versions not specified
- Netapp E-Series Santricity OS Controller: from 11.0.0, up to and including 11.60.3
- Netapp h410c Firmware: affected versions not specified
- Netapp Hci Bootstrap OS: affected versions not specified
- Netapp Hci Management Node: affected versions not specified
- Netapp Solidfire: affected versions not specified
- Netapp Steelstore Cloud Integrated Storage: affected versions not specified
- Netapp Storagegrid: up to and including 9.0.4
- Opensuse Leap: version 15.1 only; version 15.2 only
- Oracle SD-WAN Edge: version 8.2 only
Published 2020-07-30. Last modified 2026-06-17.