cbcvebase.
CVE-2020-14351
published 2020-12-03

CVE-2020-14351: A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf…

PriorityP342high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.2th percentile
A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Affected

17 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.9.6-1 (bookworm)linux 5.9.6-1 (bookworm)
linuxlinux_kernel< 5.8.175.8.17
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 4.4.0-197.2294.4.0-197.229
linuxlinux_kernel>= 0 < 4.15.0-128.1314.15.0-128.131
linuxlinux_kernel>= 0 < 4.15.0-126.1294.15.0-126.129
linuxlinux_kernel>= 0 < 5.4.0-58.645.4.0-58.64
linuxlinux_kernel>= 0 < 5.4.0-56.625.4.0-56.62
msrccm1_kernel_5.4.91-1_on_cbl_mariner_1.0
paloaltopan-os
redhatenterprise_linux
redhatenterprise_linux

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.