CVE-2020-12912
Vulnerability Summary
Timeline
Description
A potential vulnerability in the AMD extension to Linux "hwmon" service may allow an attacker to use the Linux-based Running Average Power Limit (RAPL) interface to show various side channel attacks. In line with industry partners, AMD has updated the RAPL interface to require privileged access.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.47%• Percentile: 40%
Techniques & Countermeasures
- CWE-749•Exposed Dangerous Method or Function
The product provides an Applications Programming Interface (API) or similar interface for interaction with external actors, but the interface includes a dangerous method or function that is not properly restricted.
- CWE-203•Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.
Affected Systems
- debian•linux
< 5.9.9-1 | < 5.9.9-1 | < 5.9.9-1 | < 5.9.9-1
- ubuntu•linux
all
- ubuntu•linux-aws
all
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-azure
all | all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-gcp
all
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-edge
all
- ubuntu•linux-hwe
all
- ubuntu•linux-hwe-5.8
< 5.8.0-34.37~20.04.2
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-lts-xenial
all
- ubuntu•linux-oracle-5.0
all
- ubuntu•linux-oracle-5.3
all
References (8)
- https://www.amd.com/en/corporate/product-security
- https://ubuntu.com/security/CVE-2020-12912
- https://lore.kernel.org/stable/238e3cf7-582f-a265-5300-9b44948107b0@roeck-us.net/T/#ma48754bff34127867149bf466fc2f9c2deea3960
- https://bugzilla.redhat.com/show_bug.cgi?id=1897402
- https://support.lenovo.com/lu/uk/product_security/LEN-50481
- https://ubuntu.com/security/notices/USN-4678-1
- https://www.cve.org/CVERecord?id=CVE-2020-12912
- https://security-tracker.debian.org/tracker/CVE-2020-12912