CVE-2020-25656: Debian Linux
Medium severity, CVSS 4.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.
Affected products
- Debian Debian Linux: version 9.0 only
- Linux Linux Kernel: before 5.10 (fixed in 5.10); version 5.10 only
- Red Hat Enterprise Linux: version 7.0 only; version 8.0 only
- Starwindsoftware Starwind Virtual San: version v8 only
Published 2020-12-02. Last modified 2026-06-17.