CVE-2020-25671: Use After Free
A vulnerability was found in Linux Kernel, where a refcount leak in llcpsockconnect() causing use-after-free which might lead to privilege escalations.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2020-25671?
CVE-2020-25671 is considered a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2020-25671?
To fix CVE-2020-25671, users should upgrade to patched versions of the Linux Kernel, such as 5.10.223-1 or later.
What causes CVE-2020-25671?
CVE-2020-25671 is caused by a refcount leak in the llcp_sock_connect() function, leading to a use-after-free condition.
Which Linux Kernel versions are affected by CVE-2020-25671?
CVE-2020-25671 affects Linux Kernel versions from 3.6 to 4.4.267, 4.5 to 4.9.267, 4.10 to 4.14.231, 4.15 to 4.19.187, 4.20 to 5.4.112, and 5.5 to 5.11.14.
Is CVE-2020-25671 a known vulnerability for Fedora?
Yes, CVE-2020-25671 is a known vulnerability that affects specific versions of Fedora, specifically Fedora 32, 33, and 34.