CVE-2020-28941: Debian Linux

Medium severity, CVSS 5.5. EPSS: 0.3% chance of exploitation in the next 30 days.

An issue was discovered in drivers/accessibility/speakup/spk_ttyio.c in the Linux kernel through 5.9.9. Local attackers on systems with the speakup driver could cause a local denial of service attack, aka CID-d41227544427. This occurs because of an invalid free when the line discipline is used more than once.

Affected products

  • Debian Debian Linux: version 9.0 only
  • Fedoraproject Fedora: version 32 only; version 33 only
  • Linux Linux Kernel: up to and including 5.9.9

Published 2020-11-19. Last modified 2026-06-17.