ShadowTrackr

Search the CVE vulnerability database

Look up vulnerabilities by software, product or CVE number.

← Back to results

CVE-2020-25668

A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.
An official patch is available. Apply the patch as soon as possible.
7.0
CVSS
6.4
ShadowTrackr
NO
CISA KEV
-
NCSC.nl
CVSS v4.0 Metrics
Exploitability
Attack VectorLocal
ComplexityHigh
RequirementsPresent
PrivilegesLow
User InteractionNone
Threat
Exploit MaturityPoC
Vulnerable System
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Subsequent System
ConfidentialityNone
IntegrityNone
AvailabilityNone
Supplemental
SafetyNegligible
AutomatableYes
RecoveryAutomatic
Value DensityConcentrated
UrgencyMedium
Patch StatusOfficial Patch

Change Log
DateSourceChangesScore
2026-07-21PoCE: U→P4.4 → 6.4
2026-07-21nvdAV: P→L, PR: H→L, UI: A→N, VC: N→H, VI: N→H, VA: N→H0.0 → 4.4
2026-07-21nvdpatch: Unavailable→Official Patch0.0 → 0.0
2026-07-21cve.orginitial, patch: Unavailable0.0

Affected Software
VendorProductVersion
debiandebian_linux9.0
linuxlinux_kernel≥ 4.15, < 4.19.155
linuxlinux_kernel≥ 4.20, < 5.4.75
linuxlinux_kernel≥ 5.5, < 5.9.5
linuxlinux_kernel< 4.4.242
linuxlinux_kernel≥ 4.5, < 4.9.242
linuxlinux_kernel≥ 4.10, < 4.14.204
n/aLinux Kernel5.9.2
netapp500f_firmwareAll versions
netappa250_firmwareAll versions
netappcloud_backupAll versions
netapph300e_firmwareAll versions
netapph300s_firmwareAll versions
netapph410c_firmwareAll versions
netapph410s_firmwareAll versions
netapph500e_firmwareAll versions
netapph500s_firmwareAll versions
netapph700e_firmwareAll versions
netapph700s_firmwareAll versions
netappsolidfire_\&_hci_management_nodeAll versions
netappsolidfire_baseboard_management_controller_firmwareAll versions
Published: 2021-05-26