CVE-2020-8649
published 2020-02-06CVE-2020-8649: There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
PriorityP424medium5.9CVSS 3.1
AVPACLPRLUINSUCHINAH
EPSS
0.49%
39.3th percentile
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 5.5.13-1 (bookworm) | linux 5.5.13-1 (bookworm) |
| linux | linux_kernel | <= 5.5.2 | — |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 5.5.13-1 | 5.5.13-1 |
| linux | linux_kernel | >= 0 < 4.4.0-178.208 | 4.4.0-178.208 |
| linux | linux_kernel | >= 0 < 4.4.0-184.214 | 4.4.0-184.214 |
| linux | linux_kernel | >= 0 < 4.15.0-99.100 | 4.15.0-99.100 |
| linux | linux_kernel | >= 0 < 4.15.0-106.107 | 4.15.0-106.107 |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cm1_kernel_5.4.91-11_on_cbl_mariner_1.0 | — | — |
| opensuse | leap | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv6.1MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2020-06-09·CVSS 4.4
CVE-2020-8649 [MEDIUM] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8647)
It was discovered that the virtual terminal implementation in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash) or expose sensitive
information. (CVE-2020-8648)
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8649)
It was discovered that the Serial CAN interface driver i
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2020-05-01·CVSS 6.1
CVE-2020-8649 [MEDIUM] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8647)
It was discovered that the virtual terminal implementation in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash) or expose sensitive
information. (CVE-2020-8648)
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8649)
Microsoft
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
vendor_msrc·2020-02-11·CVSS 5.9
CVE-2020-8649 [MEDIUM] CWE-416 There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
mitre: mitre
Red Hat
kernel: invalid read location in vgacon_invert_region function in drivers/video/console/vgacon.c
vendor_redhat·2020-01-30·CVSS 5.9
CVE-2020-8649 [MEDIUM] CWE-416 kernel: invalid read location in vgacon_invert_region function in drivers/video/console/vgacon.c
kernel: invalid read location in vgacon_invert_region function in drivers/video/console/vgacon.c
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
A flaw was found in the Linux kernel’s implementation of the invert video code on VGA consoles when a local attacker attempts to resize the console. An out-of-bounds read can occur, leaking information to the console.
Statement: This flaw is rated as a having Moderate impact, it is an infoleak that is written to the screen.
Mitigation: Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation b
Debian
CVE-2020-8649: linux - There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the...
vendor_debian·2020·CVSS 5.9
CVE-2020-8649 [MEDIUM] CVE-2020-8649: linux - There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the...
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
Scope: local
bookworm: resolved (fixed in 5.5.13-1)
bullseye: resolved (fixed in 5.5.13-1)
forky: resolved (fixed in 5.5.13-1)
sid: resolved (fixed in 5.5.13-1)
trixie: resolved (fixed in 5.5.13-1)
GHSA
GHSA-3fg2-94qq-385g: There is a use-after-free vulnerability in the Linux kernel through 5
ghsa_unreviewed·2022-05-24
CVE-2020-8649 [LOW] CWE-416 GHSA-3fg2-94qq-385g: There is a use-after-free vulnerability in the Linux kernel through 5
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
OSV
Kernel Live Patch Security Notice
osv·2020-06-09·CVSS 4.4
CVE-2020-8647 [MEDIUM] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8647)
It was discovered that the virtual terminal implementation in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash) or expose sensitive
information. (CVE-2020-8648)
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8649)
It was discovered that the Serial CAN interface driver in the Linux kernel
did not properly initialize data. A local attack
OSV
Kernel Live Patch Security Notice
osv·2020-05-01·CVSS 6.1
CVE-2020-8647 [MEDIUM] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8647)
It was discovered that the virtual terminal implementation in the Linux
kernel contained a race condition. A local attacker could possibly use this
to cause a denial of service (system crash) or expose sensitive
information. (CVE-2020-8648)
It was discovered that the virtual terminal implementation in the Linux
kernel did not properly handle resize events. A local attacker could use
this to expose sensitive information. (CVE-2020-8649)
Kernel
vgacon: Fix a UAF in vgacon_invert_region
kernel_security·2020-03-04
CVE-2020-8647 vgacon: Fix a UAF in vgacon_invert_region
vgacon: Fix a UAF in vgacon_invert_region
When syzkaller tests, there is a UAF:
BUG: KASan: use after free in vgacon_invert_region+0x9d/0x110 at addr
ffff880000100000
Read of size 2 by task syz-executor.1/16489
page:ffffea0000004000 count:0 mapcount:-127 mapping: (null)
index:0x0
page flags: 0xfffff00000000()
page dumped because: kasan: bad access detected
CPU: 1 PID: 16489 Comm: syz-executor.1 Not tainted
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS
rel-1.9.3-0-ge2fc41e-prebuilt.qemu-project.org 04/01/2014
Call Trace:
[] dump_stack+0x1e/0x20
[] kasan_report+0x577/0x950
[] __asan_load2+0x62/0x80
[] vgacon_invert_region+0x9d/0x110
[] invert_screen+0xe5/0x470
[] set_selection+0x44b/0x12f0
[] tioclinux+0xee/0x490
[] vt_ioctl+0xff4/0x2670
[] tty_ioctl+0x46a/0x1a10
[] do_vfs_ioc
OSV
CVE-2020-8649: There is a use-after-free vulnerability in the Linux kernel through 5
osv·2020-02-06·CVSS 5.9
CVE-2020-8649 [MEDIUM] CVE-2020-8649: There is a use-after-free vulnerability in the Linux kernel through 5
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2020-27418 kernel: User after free via vgacon_invert_region() function
bugzilla·2023-09-01·CVSS 4.4
CVE-2020-27418 [MEDIUM] CVE-2020-27418 kernel: User after free via vgacon_invert_region() function
CVE-2020-27418 kernel: User after free via vgacon_invert_region() function
A Use After Free vulnerability was found in vgacon_invert_region in drivers/video/console/vgacon.c in Low level VGA based console driver in Linux Kernel. In this flaw, a local privileged attacker may crash the system due to a missing sanity check and cause a denial of service problem.
References:
https://patchwork.freedesktop.org/patch/356372/
http://fedora.com
Discussion:
Hi, based on the referenced patch and description, this looks to have been fixed upstream in 513dc792d606 ("vgacon: Fix a UAF in vgacon_invert_region") (v5.6-rc5), which already was assigned CVE-2020-8647 and CVE-2020-8649; is this a duplicate CVE assignment?
Thanks for any clarity.
Bugzilla
CVE-2019-8649 webkitgtk: Incorrect state management leading to universal cross-site scripting
bugzilla·2020-09-07·CVSS 6.1
CVE-2019-8649 [MEDIUM] CVE-2019-8649 webkitgtk: Incorrect state management leading to universal cross-site scripting
CVE-2019-8649 webkitgtk: Incorrect state management leading to universal cross-site scripting
WebKitGTK Security Advisory WSA-2019-0004 describes the following issue:
CVE-2019-8649
Processing maliciously crafted web content may lead to universal cross site scripting. A logic issue existed in the handling of synchronous page loads. This issue was addressed with improved state management.
Versions affected: WebKitGTK before 2.24.4 and WPE WebKit before 2.24.3.
Discussion:
External References:
https://webkitgtk.org/security/WSA-2019-0004.html
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:4035 https://access.redhat.com/errata/RHSA-2020:4035
---
This bug is now closed. Further updates for individual products will be reflected
Bugzilla
CVE-2020-8649 kernel: invalid read location in vgacon_invert_region function in drivers/video/console/vgacon.c
bugzilla·2020-02-13·CVSS 5.9
CVE-2020-8649 [MEDIUM] CVE-2020-8649 kernel: invalid read location in vgacon_invert_region function in drivers/video/console/vgacon.c
CVE-2020-8649 kernel: invalid read location in vgacon_invert_region function in drivers/video/console/vgacon.c
A flaw was found in the Linux kernels implementation of VGA local console in the vgacon_invert_region functionality. An attacker with local physical access to a "VGA console" (think local virtual console) who is able to issue a terminal resize request could possibly cause a leak of information to the local console.
Reference:
https://bugzilla.kernel.org/show_bug.cgi?id=206357
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/patch/?id=513dc792d6060d5ef572e43852683097a8420f56
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1802558]
---
This issues was fixed for Fedora with the 5.4.25 stable kernel updates.
---
Statement:
Bugzilla
CVE-2020-8649 kernel: use-after-free in vgacon_invert_region function in drivers/video/console/vgacon.c [fedora-all]
bugzilla·2020-02-13·CVSS 5.9
CVE-2020-8649 [MEDIUM] CVE-2020-8649 kernel: use-after-free in vgacon_invert_region function in drivers/video/console/vgacon.c [fedora-all]
CVE-2020-8649 kernel: use-after-free in vgacon_invert_region function in drivers/video/console/vgacon.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this is
http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.htmlhttps://bugzilla.kernel.org/show_bug.cgi?id=206357https://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://www.debian.org/security/2020/dsa-4698http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00039.htmlhttps://bugzilla.kernel.org/show_bug.cgi?id=206357https://lists.debian.org/debian-lts-announce/2020/06/msg00011.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00012.htmlhttps://lists.debian.org/debian-lts-announce/2020/06/msg00013.htmlhttps://www.debian.org/security/2020/dsa-4698
2020-02-06
Published