cbcvebase.
CVE-2020-27825
published 2020-12-11

CVE-2020-27825: A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu…

PriorityP423medium5.7CVSS 3.1
AVLACHPRHUINSUCHINAH
EPSS
0.28%
19.5th percentile
A use-after-free flaw was found in kernel/trace/ring_buffer.c in Linux kernel (before 5.10-rc1). There was a race problem in trace_open and resize of cpu buffer running parallely on different cpus, may cause a denial of service problem (DOS). This flaw could even allow a local attacker with special user privilege to a kernel information leak threat.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianlinux< linux 5.9.6-1 (bookworm)linux 5.9.6-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
linuxlinux_kernel>= 0 < 5.9.6-15.9.6-1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_mrg

CVSS provenance

nvdv3.15.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H
nvdv2.05.4MEDIUMAV:L/AC:M/Au:N/C:P/I:N/A:C
osv5.7MEDIUM
vendor_debian5.7MEDIUM
vendor_redhat5.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.