CVE-2020-8647
published 2020-02-06CVE-2020-8647: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
PriorityP426medium6.1CVSS 3.1
AVLACLPRLUINSUCLINAH
EPSS
0.41%
33.5th percentile
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.5.13-1 (bookworm) | linux 5.5.13-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 5.5.2 | — |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 4.4.0-178.208 | 4.4.0-178.208 |
| linux | linux_kernel | >= 0 < 4.4.0-184.214 | 4.4.0-184.214 |
| linux | linux_kernel | >= 0 < 4.15.0-99.100 | 4.15.0-99.100 |
| linux | linux_kernel | >= 0 < 4.15.0-106.107 | 4.15.0-106.107 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-11_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_msrc6.1MEDIUM
vendor_redhat6.1MEDIUM
vendor_ubuntu6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jmx4-6cgp-jv4x: There is a use-after-free vulnerability in the Linux kernel through 5
ghsa_unreviewed·2022-05-24
CVE-2020-8647 [LOW] CWE-416 GHSA-jmx4-6cgp-jv4x: There is a use-after-free vulnerability in the Linux kernel through 5
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
OSV
Kernel Live Patch Security Notice
osv·2020-06-09·CVSS 4.4
CVE-2020-8647 [MEDIUM] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8647)
It was discovered that the virtual terminal implementation in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash) or expose sensitive
information. (CVE-2020-8648)
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8649)
It was discovered that the Serial CAN interface driver in the Linux kernel
did not properly initialize data. A local attack
OSV
Kernel Live Patch Security Notice
osv·2020-05-01·CVSS 6.1
CVE-2020-8647 [MEDIUM] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8647)
It was discovered that the virtual terminal implementation in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash) or expose sensitive
information. (CVE-2020-8648)
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8649)
Kernel
vgacon: Fix a UAF in vgacon_invert_region
kernel_security·2020-03-04
CVE-2020-8647 vgacon: Fix a UAF in vgacon_invert_region
vgacon: Fix a UAF in vgacon_invert_region
When syzkaller tests, there is a UAF:
BUG: KASan: use after free in vgacon_invert_region+0x9d/0x110 at addr
ffff880000100000
Read of size 2 by task syz-executor.1/16489
page:ffffea0000004000 count:0 mapcount:-127 mapping: (null)
index:0x0
page flags: 0xfffff00000000()
page dumped because: kasan: bad access detected
CPU: 1 PID: 16489 Comm: syz-executor.1 Not tainted
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
rel-1.9.3-0-ge2fc41e-prebuilt.qemu-project.org 04/01/2014
Call Trace:
[] dump_stack+0x1e/0x20
[] kasan_report+0x577/0x950
[] __asan_load2+0x62/0x80
[] vgacon_invert_region+0x9d/0x110
[] invert_screen+0xe5/0x470
[] set_selection+0x44b/0x12f0
[] tioclinux+0xee/0x490
[] vt_ioctl+0xff4/0x2670
[] tty_ioctl+0x46a/0x1a10
[] do_vfs_ioc
OSV
CVE-2020-8647: There is a use-after-free vulnerability in the Linux kernel through 5
osv·2020-02-06·CVSS 6.1
CVE-2020-8647 [MEDIUM] CVE-2020-8647: There is a use-after-free vulnerability in the Linux kernel through 5
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2020-06-09·CVSS 4.4
CVE-2020-8649 [MEDIUM] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8647)
It was discovered that the virtual terminal implementation in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash) or expose sensitive
information. (CVE-2020-8648)
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8649)
It was discovered that the Serial CAN interface driver i
Android
CVE-2020-8647: Kernel TTY support
vendor_android·2020-06-01·CVSS 6.1
CVE-2020-8647 [MEDIUM] CVE-2020-8647: Kernel TTY support
Android Security Bulletin 2020-06-01
CVE: CVE-2020-8647
Severity: HIGH
Type: EoP
Component: Kernel TTY support
References: A-149079134
Upstream kernel
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2020-05-01·CVSS 6.1
CVE-2020-8649 [MEDIUM] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8647)
It was discovered that the virtual terminal implementation in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash) or expose sensitive
information. (CVE-2020-8648)
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8649)
Microsoft
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
vendor_msrc·2020-02-11·CVSS 6.1
CVE-2020-8647 [MEDIUM] CWE-416 There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Customer Action Req
Red Hat
kernel: out-of-bounds read in in vc_do_resize function in drivers/tty/vt/vt.c
vendor_redhat·2020-01-30·CVSS 6.1
CVE-2020-8647 [MEDIUM] CWE-200 kernel: out-of-bounds read in in vc_do_resize function in drivers/tty/vt/vt.c
kernel: out-of-bounds read in in vc_do_resize function in drivers/tty/vt/vt.c
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
A flaw was found in the Linux kernel’s virtual console resize functionality. An attacker with local access to virtual consoles can use the virtual console resizing code to gather kernel internal data structures.
Statement: This flaw is rated as having Moderate impact because the information leak is limited.
Mitigation: The attack vector can be significantly reduced by preventing users from being able to log into the local virtual console.
See the instructions on disabling local login here: https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/6/html/managing_smart_car
Debian
CVE-2020-8647: linux - There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the...
vendor_debian·2020·CVSS 6.1
CVE-2020-8647 [MEDIUM] CVE-2020-8647: linux - There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the...
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vc_do_resize function in drivers/tty/vt/vt.c.
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed in 5.5.13-1)
sid: resolved (fixed in 5.5.13-1)
trixie: resolved (fixed in 5.5.13-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27418 kernel: User after free via vgacon_invert_region() function
bugzilla·2023-09-01·CVSS 4.4
CVE-2020-27418 [MEDIUM] CVE-2020-27418 kernel: User after free via vgacon_invert_region() function
CVE-2020-27418 kernel: User after free via vgacon_invert_region() function
A Use After Free vulnerability was found in vgacon_invert_region in drivers/video/console/vgacon.c in Low level VGA based console driver in Linux Kernel. In this flaw, a local privileged attacker may crash the system due to a missing sanity check and cause a denial of service problem.
References:
https://patchwork.freedesktop.org/patch/356372/
http://fedora.com
Discussion:
Hi, based on the referenced patch and description, this looks to have been fixed upstream in 513dc792d606 ("vgacon: Fix a UAF in vgacon_invert_region") (v5.6-rc5), which already was assigned CVE-2020-8647 and CVE-2020-8649; is this a duplicate CVE assignment?
Thanks for any clarity.
Bugzilla
CVE-2020-8647 kernel: out-of-bounds read in in vc_do_resize function in drivers/tty/vt/vt.c
bugzilla·2020-02-13·CVSS 6.1
CVE-2020-8647 [MEDIUM] CVE-2020-8647 kernel: out-of-bounds read in in vc_do_resize function in drivers/tty/vt/vt.c
CVE-2020-8647 kernel: out-of-bounds read in in vc_do_resize function in drivers/tty/vt/vt.c
An out of bounds read vulnerability in the virtual console/virtual terminal resize functionality. An attacker with a local account can use the resize functionality to possibly leak kernel internal information to the local console which may be captured for use in a further attack to increase the reliability and successfulness of the next attack.
Reference:
Kernel Bugzilla: https://bugzilla.kernel.org/show_bug.cgi?id=206359
Proposed patch: https://lkml.org/lkml/2020/3/1/415
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1802564]
---
This issue was fixed for Fedora with the 5.5.9 stable kernel updates.
---
Mitigation:
The attack vector can be significantly
Bugzilla
CVE-2020-8647 kernel: use-after-free in vc_do_resize function in drivers/tty/vt/vt.c [fedora-all]
bugzilla·2020-02-13·CVSS 6.1
CVE-2020-8647 [MEDIUM] CVE-2020-8647 kernel: use-after-free in vc_do_resize function in drivers/tty/vt/vt.c [fedora-all]
CVE-2020-8647 kernel: use-after-free in vc_do_resize function in drivers/tty/vt/vt.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multipl
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.htmlhttps://bugzilla.kernel.org/show_bug.cgi?id=206359https://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://www.debian.org/security/2020/dsa-4698http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.htmlhttps://bugzilla.kernel.org/show_bug.cgi?id=206359https://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://www.debian.org/security/2020/dsa-4698
2020-02-06
Published