ZeroHour

CVE-2020-25656

PoC ×2
CVSS 3.1
4.1 medium
EPSS
<1%p37
Published
()
Modified
Description

A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.

Vendors
linuxredhatdebianstarwindsoftware
Products
linux kernel, enterprise linux, debian linux, starwind virtual san
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.