imPC@ndo IT

Tracker / CVE-2020-25220

CVE-2020-25220

High 7.8

The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.

Affected products and versions

linux linux_kernel · 4.14 → 4.14.194
linux linux_kernel · 4.19 → 4.19.140
linux linux_kernel · 4.9.0 → 4.9.233

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References