A buffer over-read (at the framebuffer layer) in the fbcon code in the Linux kernel before 5.8.15 could be used by local attackers to read kernel memory, aka CID-6735b4632def.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-28915.json"
[ { "events": [ { "introduced": "0" }, { "fixed": "5.8.15" } ] } ]