Ubuntu 18.04 Linux kernel i915 incomplete fix for CVE-2019-14615
CVE-2020-8832

5.5MEDIUM

Key Information:

Vendor

Ubuntu

Vendor
CVE Published:
10 April 2020

What is CVE-2020-8832?

The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.

Affected Version(s)

18.04 LTS (bionic) Linux kernel 4.15.x kernels < 4.15.0-91.92

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Gregory Herrero
.
CVE-2020-8832 : Ubuntu 18.04 Linux kernel i915 incomplete fix for CVE-2019-14615