CVE-2020-25220

CVSS v3.1 7.8 (High)
78% Progress
CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.04 % (15th)
0.04% Progress
Affected Products 1

The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.

Weaknesses
CWE-416
Use After Free
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2020-09-10 02:15:11
(4 years ago)
Updated Date
2021-01-20 14:25:46
(3 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 4.9.0 version and prior 4.9.233 version cpe:2.3:o:linux:linux_kernel >= 4.9.0 < 4.9.233
  Linux Kernel from 4.14 version and prior 4.14.194 version cpe:2.3:o:linux:linux_kernel >= 4.14 < 4.14.194
  Linux Kernel from 4.19 version and prior 4.19.140 version cpe:2.3:o:linux:linux_kernel >= 4.19 < 4.19.140
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...