cbcvebase.
CVE-2020-25668
published 2021-05-26

CVE-2020-25668: A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.

PriorityP434high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
1.03%
60.2th percentile
A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.

Affected

16 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.9.6-1 (bookworm)linux 5.9.6-1 (bookworm)
linuxlinux_kernel< 4.4.2424.4.242
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 4.4.0-198.2304.4.0-198.230
linuxlinux_kernel>= 0 < 4.15.0-129.1324.15.0-129.132
linuxlinux_kernel>= 0 < 5.4.0-59.655.4.0-59.65
linuxlinux_kernel>= 4.10 < 4.14.2044.14.204
linuxlinux_kernel>= 4.15 < 4.19.1554.19.155
linuxlinux_kernel>= 4.20 < 5.4.755.4.75
linuxlinux_kernel>= 4.5 < 4.9.2424.9.242
linuxlinux_kernel>= 5.5 < 5.9.55.9.5

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv8.2HIGH
vendor_ubuntu8.2HIGH
vendor_debian7.0HIGH
vendor_redhat7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.