Bugzilla – Bug 1214919
VUL-0: CVE-2020-27418: kernel: user after free via vgacon_invert_region() function
Last modified: 2023-09-04 06:21:40 UTC
CVE-2020-27418 A Use After Free vulnerability was found in vgacon_invert_region in drivers/video/console/vgacon.c in Low level VGA based console driver in Linux Kernel. In this flaw, a local privileged attacker may crash the system due to a missing sanity check and cause a denial of service problem. References: https://patchwork.freedesktop.org/patch/356372/ http://fedora.com References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2020-27418 https://bugzilla.redhat.com/show_bug.cgi?id=2236834 https://www.cve.org/CVERecord?id=CVE-2020-27418 http://fedora.com https://patchwork.freedesktop.org/patch/356372/
Already fixed in all SUSE and openSUSE. https://github.com/openSUSE/kernel/commit/513dc792d6060d5ef572e43852683097a8420f56 Closing bug as fixed.