mirror of
https://github.com/0xMarcio/cve.git
synced 2026-06-05 23:16:42 +02:00
32 lines
1.5 KiB
Markdown
32 lines
1.5 KiB
Markdown
### [CVE-2020-25220](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-25220)
|
|

|
|

|
|

|
|
|
|
### Description
|
|
|
|
The Linux kernel 4.9.x before 4.9.233, 4.14.x before 4.14.194, and 4.19.x before 4.19.140 has a use-after-free because skcd->no_refcnt was not considered during a backport of a CVE-2020-14356 patch. This is related to the cgroups feature.
|
|
|
|
### POC
|
|
|
|
#### Reference
|
|
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.194
|
|
- https://cdn.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.9.233
|
|
|
|
#### Github
|
|
- https://github.com/404notf0und/CVE-Flow
|
|
- https://github.com/ARPSyndicate/cvemon
|
|
- https://github.com/alphaSeclab/sec-daily-2020
|
|
- https://github.com/kdn111/linux-kernel-exploitation
|
|
- https://github.com/khanhdn111/linux-kernel-exploitation
|
|
- https://github.com/khanhdz-06/linux-kernel-exploitation
|
|
- https://github.com/khanhdz191/linux-kernel-exploitation
|
|
- https://github.com/khanhhdz/linux-kernel-exploitation
|
|
- https://github.com/khanhhdz06/linux-kernel-exploitation
|
|
- https://github.com/khanhnd123/linux-kernel-exploitation
|
|
- https://github.com/knd06/linux-kernel-exploitation
|
|
- https://github.com/ndk191/linux-kernel-exploitation
|
|
- https://github.com/ssr-111/linux-kernel-exploitation
|
|
- https://github.com/xairy/linux-kernel-exploitation
|
|
|