Description
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.
Published: 2020-04-09
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

Vendor Solution

Update to linux kernel 4.15.0-91.92 or newer, or apply the following commits: (20ccd4d3f689ac14dce8632d76769be0ac952060) drm/i915: Use same test for eviction and submitting kernel context (1803fcbca2e444f7972430c4dc1c3e98c6ee1bc9) drm/i915: Define an engine class enum for the uABI (ae6c4574782dbfebcbf1f7e3620bcaf58ceb69e3) drm/i915: Force the switch to the i915->kernel_context (f58d13d5717938d4dfcc82a2eeba0a6d7644f6e5) drm/i915: Move GT powersaving init to i915_gem_init() (cc6a818ad6bdb0d3008314cbd0fc9c9a2cd02695) drm/i915: Move intel_init_clock_gating() to i915_gem_init() (d378a3efb819e6d1992127122d957337571b4594) drm/i915: Inline intel_modeset_gem_init() (f4e15af7e21861445821d5f09922ef7e695269a1) drm/i915: Mark the context state as dirty/written (d2b4b97933f5adacfba42dc3b9200d0e21fbe2c4) drm/i915: Record the default hw state after reset upon load

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-29675 The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.
Ubuntu USN Ubuntu USN USN-4302-1 Linux kernel vulnerabilities
History

No history.

Subscriptions

Canonical Ubuntu Linux
Netapp Aff 8300 Aff 8300 Firmware Aff 8700 Aff 8700 Firmware Aff A220 Aff A220 Firmware Aff A320 Aff A320 Firmware Aff A400 Aff A400 Firmware Aff A700s Aff A700s Firmware Aff C190 Aff C190 Firmware Cloud Backup Fas2720 Fas2720 Firmware Fas2750 Fas2750 Firmware Fas8300 Fas8300 Firmware Fas8700 Fas8700 Firmware Fas Baseboard Management Controller A220 Fas Baseboard Management Controller A220 Firmware Fas Baseboard Management Controller A320 Fas Baseboard Management Controller A320 Firmware Fas Baseboard Management Controller A400 Fas Baseboard Management Controller A400 Firmware Fas Baseboard Management Controller A800 Fas Baseboard Management Controller A800 Firmware Fas Baseboard Management Controller C190 Fas Baseboard Management Controller C190 Firmware H300e H300e Firmware H300s H300s Firmware H410c H410c Firmware H410s H410s Firmware H500e H500e Firmware H500s H500s Firmware H610c H610c Firmware H610s H610s Firmware H615c H615c Firmware H700e H700e Firmware H700s H700s Firmware Solidfire \& Hci Management Node Solidfire Baseboard Management Controller Solidfire Baseboard Management Controller Firmware Steelstore Cloud Integrated Storage
cve-icon MITRE

Status: PUBLISHED

Assigner: canonical

Published:

Updated: 2024-09-17T02:51:41.129Z

Reserved: 2020-02-10T00:00:00.000Z

Link: CVE-2020-8832

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-04-10T00:15:11.990

Modified: 2024-11-21T05:39:31.790

Link: CVE-2020-8832

cve-icon Redhat

Severity : Moderate

Publid Date: 2020-03-25T00:00:00Z

Links: CVE-2020-8832 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses