CVE-2020-25656: Debian Linux

Medium severity, CVSS 4.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Linux Linux Kernel: before 5.10 (fixed in 5.10); version 5.10 only
  • Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
  • Starwindsoftware Starwind Virtual San: version v8 only

Published 2020-12-02. Last modified 2026-06-17.