Skip to content

kernel CVE-2020-25656

Moderate
etungsten published GHSA-w2rr-82gq-x4q3 Jan 15, 2021

Package

kernel (bottlerocket)

Affected versions

< 1.0.5

Patched versions

1.0.5

Description

A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds.

Severity

Moderate

CVE ID

CVE-2020-25656

Weaknesses

No CWEs