Vulnerabilities > CVE-2020-25656 - Use After Free vulnerability in multiple products

047910
CVSS 4.1 - MEDIUM
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
HIGH
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE

Summary

A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.

Vulnerable Configurations

Part Description Count
OS
Linux
4175
OS
Redhat
2
OS
Debian
1
Application
Starwindsoftware
6

Common Weakness Enumeration (CWE)