This security advisory describes one low risk vulnerability.
Exploit availability: NoDescription
The vulnerability allows a local user to predict values of random generator.
The vulnerability exists due to en error in kern.arandom implementation. A local user that can obtain kernel PRNG state used by kern.arandom can predict future outputs of kern.arandom.
Install updates from vendor's website.Vulnerable software versions
NetBSD: 7.1, 7.1.1, 7.1.2, 7.2, 8.0CPE
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.