CVE-2020-27418
published 2023-08-22CVE-2020-27418: A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.
PriorityP417medium4.4CVSS 3.1
AVLACLPRHUINSUCHINAN
EPSS
0.22%
12.9th percentile
A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.5.13-1 (bookworm) | linux 5.5.13-1 (bookworm) |
| fedoraproject | fedora_linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
CVSS provenance
nvdv3.14.4MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
osv4.4MEDIUM
vendor_debian4.4MEDIUM
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Fedora Linux 5.9.0-rc9 Kernel vgacon_invert_region information disclosure
vuldb·2026-07-10·CVSS 4.4
CVE-2020-27418 [MEDIUM] Fedora Linux 5.9.0-rc9 Kernel vgacon_invert_region information disclosure
A vulnerability classified as problematic has been found in Fedora Linux 5.9.0-rc9. Affected by this vulnerability is the function vgacon_invert_region of the component Kernel. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2020-27418. The attack can only be initiated within the local network. No exploit exists.
OSV
CVE-2020-27418: A Use After Free vulnerability in Fedora Linux kernel 5
osv·2023-08-22·CVSS 4.4
CVE-2020-27418 [MEDIUM] CVE-2020-27418: A Use After Free vulnerability in Fedora Linux kernel 5
A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.
GHSA
GHSA-v9gh-f54x-54f5: A Use After Free vulnerability in Fedora Linux kernel 5
ghsa_unreviewed·2023-08-22
CVE-2020-27418 [MEDIUM] CWE-416 GHSA-v9gh-f54x-54f5: A Use After Free vulnerability in Fedora Linux kernel 5
A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.
Red Hat
kernel: User after free via vgacon_invert_region() function
vendor_redhat·2023-08-22·CVSS 4.4
CVE-2020-27418 [MEDIUM] CWE-416 kernel: User after free via vgacon_invert_region() function
kernel: User after free via vgacon_invert_region() function
A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.
A use-after-free vulnerability was found in the vgacon_invert_region in drivers/video/console/vgacon.c in the low-level VGA-based console driver in the Linux kernel. This flaw allows a local privileged attacker to crash the system due to a missing sanity check, causing a denial of service.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Package: kernel (Red Hat Enterprise Linux 6) - Out
Debian
CVE-2020-27418: linux - A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers...
vendor_debian·2020·CVSS 4.4
CVE-2020-27418 [MEDIUM] CVE-2020-27418: linux - A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers...
A Use After Free vulnerability in Fedora Linux kernel 5.9.0-rc9 allows attackers to obatin sensitive information via vgacon_invert_region() function.
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed in 5.5.13-1)
sid: resolved (fixed in 5.5.13-1)
trixie: resolved (fixed in 5.5.13-1)
No detection rules found.
No public exploits indexed.
2023-08-22
Published