CVE-2020-28941: Debian Linux
Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.
An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.
Affected products
- Debian Debian Linux: version 9.0 only
- Fedoraproject Fedora: version 32 only; version 33 only
- Linux Linux Kernel: up to and including 5.9.9
Published 2020-11-19. Last modified 2026-06-17.