CVE-2008-0166General(canonical / debian_linux)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that generates predictable numbers, which makes it easier for remote attackers to conduct brute force guessing attacks against cryptographic keys.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-338

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • openssl
  • ubuntu_linux

Threat summary

  • 9 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 9 classified signals
  • Peaked 8d ago at 1 mentions (2026-03-23); latest day: 1
  • 9 total mentions across 9 days

Affected systems

Products
debian_linuxopensslubuntu_linux

5 versions affected across 3 products

Deep dive

Activity timeline9 mentions / 9d
00111Mentions · 2026-03-23: 1Mentions · 2026-03-24: 1Mentions · 2026-04-02: 1Mentions · 2026-05-10: 1Mentions · 2026-05-11: 1Mentions · 2026-08-01: 1Mentions · 2026-08-02: 1Mentions · 2026-08-03: 1Mentions · 2026-08-04: 1Technical Details · 2026-04-02: 1Technical Details · 2026-08-03: 1Technical Details · 2026-08-04: 103-2303-2404-0205-1005-1108-0108-0208-0308-04
Signal classification1 categories
General
9100.0%
Referenced assets3 URLs
Full discourse9 posts
  • Juliano Rizzo@julianor
    General

    When I learned about CVE-2008-0166, it felt like being "owned ": realizing the intruder may have been inside the box all along. What you imagine quantum computers will do someday. By then, my daily life was through little encrypted corridors I trusted 100%: Shells. VPN. Chat. Git

    Post summary

    The post merely notes awareness of CVE-2008-0166 without providing technical details, exploit data, or patch information.

    02053934
    9.5K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-41940 2 - CVE-2026-3854 3 - CVE-2008-0166 4 - CVE-2026-7482 5 - CVE-2026-29202 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post merely lists the top five trending CVEs without providing any additional technical information, exploit details, or mitigation guidance.

    00031213
    1.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2026-21992 2 - CVE-2025-5777 3 - CVE-2026-3909 4 - CVE-2025-32975 5 - CVE-2008-0166 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVEs without providing any additional context such as exploits, patches, or technical details.

    00020261
    1.7K followersView on X
  • Btcandres 285⚡ 9🌊 🔦🔑🦡🥩🐇🕳️☣️6.15🛰️🆖🆙🌋@BtcAndres
    General

    Esto de RNG vulnerable no es nuevo. Y no solo aplica a Wallets de cRiPtO o bitcoin. Problemas con la entropía, leer: Debian OpenSSL Vulnerability (CVE-2008-0166) 2008 y leer sobre Android y su vulnerabilidad en el generador de números pseudoaleatorios. Ver tweet citado 👇🏽 https://t.co/81rmAjdutd

    Post summary

    The post merely points out that RNG vulnerabilities are not new, citing CVE-2008-0166 and similar Android issues, without offering PoC, exploit code, or active exploitation evidence.

    001001.1K
    35.4K followersView on X
  • Ace One Design@aceonedesign
    General

    @lopp There are large weak rng vulnerabilities that broke openssl, before crypto even existed. Tale as old as time unfortunately. What's old is new again https://nvd.nist.gov/vuln/detail/cve-2008-0166

    Post summary

    The tweet points out a weak RNG vulnerability (CVE-2008-0166) in OpenSSL, noting its historical relevance, but gives no PoC, exploit, or patch details.

    00001265
    968 followersView on X
  • ✧ 白銀のミコッテ M'aya |海外ナイト ✧@rolanberrypie
    General

    Insufficient entropy has been a common mode of failure in cryptographic systems. 2008: debian openssl cve-2008-0166 2017: ROCA smartcard vuln 2024: owner recovered lost coins by cracking Roboform rng

    Post summary

    The entry lists historical cryptographic entropy weaknesses but provides no actionable or technical details, making it a general reference.

    10000161
    2.5K followersView on X
  • B4Q@B4Quantum
    General

    2/ Early BTC used terrible RNGs: - glibc LCG seeded with Unix timestamps - Mersenne Twister with time seeds - OpenSSL Debian bug (CVE-2008-0166 — only 65,536 possible keys) - SHA256(phone_number) brain wallets We systematically test every possible key from each method.

    Post summary

    The post lists early Bitcoin RNG weaknesses and an old CVE with key enumeration details, but makes no claim about exploits, patches, or ongoing attacks.

    1000048
    296 followersView on X
  • TAKAHIRO@c_o_t
    General

    Gemini ProによればOpenSSLの脆弱性発見につながったけれど、衝突したのは SSH公開鍵らしい (他の方も CVE-2008-0166 をあげてるしあってそう?) 信頼できそうなソース(エンジニアのブログ)のタイトルもみつけてくれてた。 https://gemini.google.com/share/c1b64c38efd6

    Post summary

    The text cites an OpenSSL‑related CVE (CVE‑2008‑0166), noting a collision with SSH public keys, but does not provide any PoC, exploit details, or remediation information.

    00010141
    66 followersView on X
  • Marc Riemer@mriemer
    General

    @TheSamsPodcast @OperationAjax Check the CVE-2008-0166 fascinating story. RNG attacks are a very well known and nothing new.

    Post summary

    The tweet references CVE-2008-0166 but offers no technical, exploit, or patch information.

    0000046
    2.9K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
OScanonicalubuntu_linux6.06--
OScanonicalubuntu_linux7.04--
OScanonicalubuntu_linux7.10--
OScanonicalubuntu_linux8.04--
OSdebiandebian_linux4.0--
Appopensslopenssl---

Explore more