CVE-2020-23856: Fedoraproject Fedora

Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Use-after-Free vulnerability in cflow 1.6 in the void call(char *name, int line) function at src/parser.c, which could cause a denial of service via the pointer variable caller->callee.

Affected products

  • Fedoraproject Fedora: version 33 only; version 34 only
  • GNU Cflow: version 1.6 only

Published 2021-05-18. Last modified 2026-06-17.