CVE-2020-25668
published 2021-05-26CVE-2020-25668: A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
PriorityP434high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
1.03%
60.2th percentile
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 5.9.6-1 (bookworm) | linux 5.9.6-1 (bookworm) |
| linux | linux_kernel | < 4.4.242 | 4.4.242 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 5.9.6-1 | 5.9.6-1 |
| linux | linux_kernel | >= 0 < 4.4.0-198.230 | 4.4.0-198.230 |
| linux | linux_kernel | >= 0 < 4.15.0-129.132 | 4.15.0-129.132 |
| linux | linux_kernel | >= 0 < 5.4.0-59.65 | 5.4.0-59.65 |
| linux | linux_kernel | >= 4.10 < 4.14.204 | 4.14.204 |
| linux | linux_kernel | >= 4.15 < 4.19.155 | 4.19.155 |
| linux | linux_kernel | >= 4.20 < 5.4.75 | 5.4.75 |
| linux | linux_kernel | >= 4.5 < 4.9.242 | 4.9.242 |
| linux | linux_kernel | >= 5.5 < 5.9.5 | 5.9.5 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.2HIGH
vendor_ubuntu8.2HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2020-25668: In vt_disallocate and related functions of vt_ioctl
osv·2021-12-01
CVE-2020-25668 CVE-2020-25668: In vt_disallocate and related functions of vt_ioctl
In vt_disallocate and related functions of vt_ioctl.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.
OSV
CVE-2020-25668: A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font
osv·2021-05-26·CVSS 7.0
CVE-2020-25668 [HIGH] CVE-2020-25668: A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
OSV
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities
osv·2021-02-25·CVSS 4.1
CVE-2020-25656 [MEDIUM] linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.8, linux-kvm, linux-oracle, linux-raspi vulnerabilities
It was discovered that the console keyboard driver in the Linux kernel
contained a race condition. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2020-25656)
Minh Yuan discovered that the tty driver in the Linux kernel contained race
conditions when handling fonts. A local attacker could possibly use this to
expose sensitive information (kernel memory). (CVE-2020-25668)
Bodong Zhao discovered a use-after-free in the Sun keyboard driver
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2020-25669)
Kiyin (尹亮) discovered that the perf subsystem in the Linu
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
osv·2021-01-06·CVSS 8.2
CVE-2019-19770 [HIGH] linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
It was discovered that debugfs in the Linux kernel as used by blktrace
contained a use-after-free in some situations. A privileged local attacker
could possibly use this to cause a denial of service (system crash).
(CVE-2019-19770)
It was discovered that a race condition existed in the binder IPC
implementation in the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-0423)
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secur
OSV
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabi
osv·2021-01-06·CVSS 4.1
CVE-2020-25656 [MEDIUM] linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabi
linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-gcp, linux-gcp-5.4, linux-gke-5.4, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities
It was discovered that the console keyboard driver in the Linux kernel
contained a race condition. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2020-25656)
Minh Yuan discovered that the tty driver in the Linux kernel contained race
conditions when handling fonts. A local attacker could possibly use this to
expose sensitive information (kernel memory). (CVE-2020-25668)
Kiyin (尹亮) discovered that the perf subsystem in the Linux kernel did
not properly deallocate memory in some situations. A privileged attacker
could use this to cause a denial of
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi2, linux-snapdragon vulnerabilities
osv·2021-01-06·CVSS 5.5
CVE-2019-0148 [MEDIUM] linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi2, linux-snapdragon vulnerabilities
linux, linux-aws, linux-kvm, linux-lts-xenial, linux-raspi2, linux-snapdragon vulnerabilities
Ryan Hall discovered that the Intel 700 Series Ethernet Controllers driver
in the Linux kernel did not properly deallocate memory in some conditions.
A local attacker could use this to cause a denial of service (kernel memory
exhaustion). (CVE-2019-0148)
It was discovered that the console keyboard driver in the Linux kernel
contained a race condition. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2020-25656)
Minh Yuan discovered that the tty driver in the Linux kernel contained race
conditions when handling fonts. A local attacker could possibly use this to
expose sensitive information (kernel memory). (CVE-2020-25668)
Jinoh Kang discovered that the Xen
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-02-25·CVSS 4.1
CVE-2020-25704 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the console keyboard driver in the Linux kernel
contained a race condition. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2020-25656)
Minh Yuan discovered that the tty driver in the Linux kernel contained race
conditions when handling fonts. A local attacker could possibly use this to
expose sensitive information (kernel memory). (CVE-2020-25668)
Bodong Zhao discovered a use-after-free in the Sun keyboard driver
implementation in the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2020-25669)
Kiyin (尹亮) discovered that the perf subsystem in the Linux kernel
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-01-06·CVSS 5.5
CVE-2020-25668 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
Ryan Hall discovered that the Intel 700 Series Ethernet Controllers driver
in the Linux kernel did not properly deallocate memory in some conditions.
A local attacker could use this to cause a denial of service (kernel memory
exhaustion). (CVE-2019-0148)
It was discovered that the console keyboard driver in the Linux kernel
contained a race condition. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2020-25656)
Minh Yuan discovered that the tty driver in the Linux kernel contained race
conditions when handling fonts. A local attacker could possibly use this to
expose sensitive information (kernel memory). (CVE-2020-25668)
Jinoh Kang discovered that
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-01-06·CVSS 8.2
CVE-2020-0423 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that debugfs in the Linux kernel as used by blktrace
contained a use-after-free in some situations. A privileged local attacker
could possibly use this to cause a denial of service (system crash).
(CVE-2019-19770)
It was discovered that a race condition existed in the binder IPC
implementation in the Linux kernel, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-0423)
Daniele Antonioli, Nils Ole Tippenhauer, and Kasper Rasmussen discovered
that legacy pairing and secure-connections pairing authentication in the
Bluetooth protocol could allow an unauthenti
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2021-01-06·CVSS 4.1
CVE-2020-28974 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the console keyboard driver in the Linux kernel
contained a race condition. A local attacker could use this to expose
sensitive information (kernel memory). (CVE-2020-25656)
Minh Yuan discovered that the tty driver in the Linux kernel contained race
conditions when handling fonts. A local attacker could possibly use this to
expose sensitive information (kernel memory). (CVE-2020-25668)
Kiyin (尹亮) discovered that the perf subsystem in the Linux kernel did
not properly deallocate memory in some situations. A privileged attacker
could use this to cause a denial of service (kernel memory exhaustion).
(CVE-2020-25704)
Jinoh Kang discovered that the Xen event channel i
Red Hat
kernel: race condition in fg_console can lead to use-after-free in con_font_op
vendor_redhat·2020-10-30·CVSS 7.0
CVE-2020-25668 [HIGH] CWE-362 kernel: race condition in fg_console can lead to use-after-free in con_font_op
kernel: race condition in fg_console can lead to use-after-free in con_font_op
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
A use-after-free flaw was found in the Linux kernel’s TTY driver functionality in the way the user triggers the con_font_op function. This flaw allows a local user to crash or escalate their privileges on the system or expose sensitive information (kernel memory).
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) -
Debian
CVE-2020-25668: linux - A flaw was found in Linux Kernel because access to the global variable fg_consol...
vendor_debian·2020·CVSS 7.0
CVE-2020-25668 [HIGH] CVE-2020-25668: linux - A flaw was found in Linux Kernel because access to the global variable fg_consol...
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
Scope: local
bookworm: resolved (fixed in 5.9.6-1)
bullseye: resolved (fixed in 5.9.6-1)
forky: resolved (fixed in 5.9.6-1)
sid: resolved (fixed in 5.9.6-1)
trixie: resolved (fixed in 5.9.6-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-25668 kernel: race condition in fg_console can lead to use-after-free in con_font_op
bugzilla·2020-10-30·CVSS 7.0
CVE-2020-25668 [HIGH] CVE-2020-25668 kernel: race condition in fg_console can lead to use-after-free in con_font_op
CVE-2020-25668 kernel: race condition in fg_console can lead to use-after-free in con_font_op
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
Reference:
https://www.openwall.com/lists/oss-security/2020/10/30/1
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1893288]
---
The patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=90bfdeef83f1d6c696039b6a917190dcbbad3220
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2020-25668
Bugzilla
CVE-2020-25668 kernel: race condition in fg_console can lead to use-after-free in con_font_op [fedora-all]
bugzilla·2020-10-30·CVSS 7.0
CVE-2020-25668 [HIGH] CVE-2020-25668 kernel: race condition in fg_console can lead to use-after-free in con_font_op [fedora-all]
CVE-2020-25668 kernel: race condition in fg_console can lead to use-after-free in con_font_op [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
http://www.openwall.com/lists/oss-security/2020/10/30/1http://www.openwall.com/lists/oss-security/2020/11/04/3https://bugzilla.redhat.com/show_bug.cgi?id=1893287%2Chttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=90bfdeef83f1d6c696039b6a917190dcbbad3220https://lists.debian.org/debian-lts-announce/2020/12/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00027.htmlhttps://security.netapp.com/advisory/ntap-20210702-0005/https://www.openwall.com/lists/oss-security/2020/10/30/1%2Chttps://www.openwall.com/lists/oss-security/2020/11/04/3%2Chttp://www.openwall.com/lists/oss-security/2020/10/30/1http://www.openwall.com/lists/oss-security/2020/11/04/3https://bugzilla.redhat.com/show_bug.cgi?id=1893287%2Chttps://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=90bfdeef83f1d6c696039b6a917190dcbbad3220https://lists.debian.org/debian-lts-announce/2020/12/msg00015.htmlhttps://lists.debian.org/debian-lts-announce/2020/12/msg00027.htmlhttps://security.netapp.com/advisory/ntap-20210702-0005/https://www.openwall.com/lists/oss-security/2020/10/30/1%2Chttps://www.openwall.com/lists/oss-security/2020/11/04/3%2C
2021-05-26
Published