Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2020-8649 |
CWE-ID | CWE-416 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software Subscribe |
Linux kernel Operating systems & Components / Operating system |
Vendor | Linux Foundation |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU28414
Risk: Medium
CVSSv3.1: 5.2 [CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2020-8649
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a local authenticated user to #BASIC_IMPACT#.
There is a use-after-free vulnerability in the Linux kernel through 5.5.2 in the vgacon_invert_region function in drivers/video/console/vgacon.c.
MitigationInstall update from vendor's website.
Vulnerable software versionsLinux kernel: 4.4 - 5.5.19
External linkshttp://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.4.216
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.216
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.19.109
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.173
http://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.5.9
http://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.4.25
http://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.6
Q & A
Can this vulnerability be exploited remotely?
No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.