First published: Wed Jul 29 2020(Updated: )
A flaw was found in the Linux kernel. The generation of the device ID from the network RNG internal state is predictable. The highest threat from this vulnerability is to data confidentiality.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/kernel-alt | <0:4.14.0-115.32.1.el7a | 0:4.14.0-115.32.1.el7a |
redhat/kernel-rt | <0:4.18.0-240.8.1.rt7.62.el8_3 | 0:4.18.0-240.8.1.rt7.62.el8_3 |
redhat/kernel | <0:4.18.0-240.8.1.el8_3 | 0:4.18.0-240.8.1.el8_3 |
redhat/kernel | <0:4.18.0-147.38.1.el8_1 | 0:4.18.0-147.38.1.el8_1 |
redhat/kernel-rt | <0:4.18.0-193.37.1.rt13.87.el8_2 | 0:4.18.0-193.37.1.rt13.87.el8_2 |
redhat/kernel | <0:4.18.0-193.37.1.el8_2 | 0:4.18.0-193.37.1.el8_2 |
Linux Kernel | <=5.7.11 | |
SUSE Linux | =15.1 | |
SUSE Linux | =15.2 | |
Red Hat Fedora | =31 | |
Red Hat Fedora | =32 | |
Debian Linux | =9.0 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =18.04 | |
Ubuntu | =20.04 | |
NetApp Active IQ Unified Manager for VMware vSphere | >=9.5 | |
NetApp ONTAP Mediator | ||
NetApp E-Series SANtricity OS Controller | >=11.0.0<=11.60.3 | |
NetApp Bootstrap OS | ||
NetApp SolidFire & HCI Management Node | ||
NetApp SolidFire & HCI Storage Node | ||
NetApp SteelStore Cloud Integrated Storage | ||
NetApp StorageGRID Webscale | <=9.0.4 | |
All of | ||
NetApp H410C | ||
NetApp H410C Firmware | ||
Oracle SD-WAN Edge | =8.2 | |
NetApp H410C | ||
NetApp H410C Firmware | ||
debian/linux | 5.10.223-1 5.10.234-1 6.1.129-1 6.1.128-1 6.12.20-1 6.12.21-1 |
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-16166 is classified as having a high severity level due to its potential impact on data confidentiality.
CVE-2020-16166 affects multiple versions of the Linux kernel and various distributions including Red Hat, OpenSUSE, Fedora, and Debian.
To mitigate CVE-2020-16166, update to the latest patched versions of the affected Linux kernel packages as specified by your distribution.
CVE-2020-16166 can lead to predictable device IDs from the network RNG, posing a risk to data confidentiality.
The fixed versions for the Linux kernel addressing CVE-2020-16166 include 4.14.0-115.32.1.el7a, 4.18.0-240.8.1.el8_3, among others, depending on the distribution.