cbcvebase.
CVE-2020-25671
published 2021-05-26

CVE-2020-25671: A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.

PriorityP340high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.51%
40.7th percentile
A vulnerability was found in Linux Kernel, where a refcount leak in llcp_sock_connect() causing use-after-free which might lead to privilege escalations.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 5.10.38-1 (bookworm)linux 5.10.38-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fedoraprojectfedora
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.10.38-15.10.38-1
linuxlinux_kernel>= 0 < 5.4.0-74.835.4.0-74.83
linuxlinux_kernel>= 0 < 4.4.0-222.2554.4.0-222.255
linuxlinux_kernel>= 3.6 < 4.4.2674.4.267
linuxlinux_kernel>= 4.10 < 4.14.2314.14.231
linuxlinux_kernel>= 4.15 < 4.19.1874.19.187
linuxlinux_kernel>= 4.20 < 5.4.1125.4.112
linuxlinux_kernel>= 4.5 < 4.9.2674.9.267
linuxlinux_kernel>= 5.11 < 5.11.145.11.14
linuxlinux_kernel>= 5.5 < 5.10.305.10.30

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.