CVE-2019-14615
Vulnerability Summary
Timeline
Description
Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- v2.0•LOW•Score: 1.9AV:L/AC:M/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 1.45%• Percentile: 72%
Affected Systems
- canonical•ubuntu_linux
14.04 | 16.04 | 18.04 | 19.10
- debian•linux
< 5.4.13-1 | < 5.4.13-1 | < 5.4.13-1 | < 5.4.13-1
- ubuntu•linux
all | < 4.4.0-173.203 | < 4.15.0-76.86
- ubuntu•linux-aws
< 4.4.0-1062.66 | < 4.4.0-1102.113 | < 4.15.0-1058.60
- ubuntu•linux-aws-5.0
< 5.0.0-1025.28
- ubuntu•linux-aws-fips
< 4.15.0-2018.18 | all
- ubuntu•linux-aws-hwe
< 4.15.0-1058.60~16.04.1
- ubuntu•linux-azure
< 4.15.0-1067.72~14.04.1 | < 4.15.0-1067.72 | < 5.0.0-1032.34
- ubuntu•linux-azure-5.3
< 5.3.0-1010.11~18.04.1
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fde-5.15
< 5.15.0-1114.123~20.04.1
- ubuntu•linux-azure-fips
< 4.15.0-2006.7 | all
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.4.0-1029.34 | all
- ubuntu•linux-gcp
< 4.15.0-1055.59 | < 5.0.0-1031.32
- ubuntu•linux-gcp-5.3
< 5.3.0-1012.13~18.04.1
- ubuntu•linux-gcp-edge
all
- ubuntu•linux-gcp-fips
all
- ubuntu•linux-gke
all
- ubuntu•linux-gke-4.15
< 4.15.0-1052.55
- ubuntu•linux-gke-5.0
< 5.0.0-1030.31
- ubuntu•linux-gke-5.3
< 5.3.0-1012.13~18.04.1
- ubuntu•linux-hwe
< 4.15.0-76.86~16.04.1 | < 5.3.0-28.30~18.04.1
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-kvm
< 4.4.0-1066.73 | < 4.15.0-1053.53
- ubuntu•linux-lts-xenial
< 4.4.0-173.203~14.04.1
- ubuntu•linux-oem
< 4.15.0-1067.77
- ubuntu•linux-oem-osp1
< 5.0.0-1037.42
- ubuntu•linux-oracle
< 4.15.0-1033.36~16.04.1 | < 4.15.0-1033.36
- ubuntu•linux-oracle-5.0
< 5.0.0-1011.16
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all
- ubuntu•linux-snapdragon
< 4.4.0-1133.141 | < 4.15.0-1071.78
- intel•atom_e3805
na
- intel•atom_e3815
na
- intel•atom_e3825
na
- intel•atom_e3826
na
- intel•atom_e3827
na
- intel•atom_e3845
na
- intel•atom_e620
na
- intel•atom_e620t
na
- intel•atom_e640
na
- intel•atom_e640t
na
- intel•atom_e660
na
- intel•atom_e660t
na
- intel•atom_e680
na
- intel•atom_e680t
na
Showing first 50 affected entries in server-rendered view.
References (35)
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00314.html
- https://usn.ubuntu.com/4253-1/
- https://usn.ubuntu.com/4254-1/
- https://usn.ubuntu.com/4255-1/
- https://usn.ubuntu.com/4255-2/
- https://usn.ubuntu.com/4253-2/
- https://usn.ubuntu.com/4254-2/
- http://packetstormsecurity.com/files/156185/Kernel-Live-Patch-Security-Notice-LSN-0062-1.html
- http://packetstormsecurity.com/files/156455/Kernel-Live-Patch-Security-Notice-LSN-0063-1.html
- https://usn.ubuntu.com/4285-1/
- https://usn.ubuntu.com/4287-1/
- https://usn.ubuntu.com/4286-2/
- https://usn.ubuntu.com/4287-2/
- https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
- https://usn.ubuntu.com/4284-1/
- https://usn.ubuntu.com/4286-1/
- http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00021.html
- https://support.apple.com/kb/HT211100
- http://seclists.org/fulldisclosure/2020/Mar/31
- https://ubuntu.com/security/CVE-2019-14615
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=bc8a76a152c5f9ef3b48104154a65a68a8b76946
- https://ubuntu.com/security/notices/USN-4253-1
- https://ubuntu.com/security/notices/USN-4255-1
- https://ubuntu.com/security/notices/USN-4254-1
- https://ubuntu.com/security/notices/USN-4255-2
- https://ubuntu.com/security/notices/USN-4254-2
- https://ubuntu.com/security/notices/USN-4253-2
- https://ubuntu.com/security/notices/USN-4284-1
- https://ubuntu.com/security/notices/USN-4285-1
- https://ubuntu.com/security/notices/USN-4286-1
- https://ubuntu.com/security/notices/USN-4287-1
- https://ubuntu.com/security/notices/USN-4286-2
- https://ubuntu.com/security/notices/USN-4287-2
- https://www.cve.org/CVERecord?id=CVE-2019-14615
- https://security-tracker.debian.org/tracker/CVE-2019-14615