CVE-2020-27820: Fedoraproject Fedora
Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability was found in Linux kernel, where a use-after-frees in nouveau's postclose() handler could happen if removing device (that is not common to remove video card physically without power-off, but same happens if "unbind" the driver).
Affected products
- Fedoraproject Fedora: version 33 only
- Linux Linux Kernel: after 2.6.12, before 5.4.162 (fixed in 5.4.162); after 5.5, before 5.10.82 (fixed in 5.10.82); after 5.11, before 5.15.5 (fixed in 5.15.5); version 2.6.12 only
- Oracle Communications Cloud Native Core Binding Support Function: version 22.1.3 only
- Oracle Communications Cloud Native Core Network Exposure Function: version 22.1.1 only
- Oracle Communications Cloud Native Core Policy: version 22.2.0 only
Published 2021-11-03. Last modified 2026-06-17.