CVE-2020-25220: Linux Kernel
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.
Affected products
- Linux Linux Kernel: from 4.9.0, before 4.9.233 (fixed in 4.9.233); from 4.14, before 4.14.194 (fixed in 4.14.194); from 4.19, before 4.19.140 (fixed in 4.19.140)
Published 2020-09-10. Last modified 2026-06-17.