CVE-2020-8694
Vulnerability Summary
Timeline
Description
Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
CVSS Metrics
- v3.1•MEDIUM•Score: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- v2.0•LOW•Score: 2.1AV:L/AC:L/Au:N/C:P/I:N/A:N
EPSS Trends
Current EPSS score: 0.45%• Percentile: 39%
Affected Systems
- alpine•intel-ucode
< 20201112-r0 | < 20201112-r0 | < 20201112-r0 | < 20201112-r0 | < 20201112-r0 | < 20201112-r0 | < 20201112-r0 | < 20201112-r0 | < 20201112-r0 | < 20201112-r0 | < 20201112-r0 | < 20201112-r0
- debian•linux
< 5.9.9-1 | < 5.9.9-1 | < 5.9.9-1 | < 5.9.9-1
- ubuntu•linux
< 3.13.0-183.234 | < 4.4.0-194.226 | < 4.15.0-123.126 | < 5.4.0-53.59
- ubuntu•linux-aws
< 4.4.0-1082.86
- ubuntu•linux-aws-5.0
all
- ubuntu•linux-aws-5.3
all
- ubuntu•linux-aws-fips
< 4.15.0-2031.32 | all | < 5.4.0-1069.73+fips2
- ubuntu•linux-azure
< 4.15.0-1100.111~14.04.1 | all
- ubuntu•linux-azure-5.3
all
- ubuntu•linux-azure-edge
all
- ubuntu•linux-azure-fde
all
- ubuntu•linux-azure-fips
< 4.15.0-2013.15 | all | < 5.4.0-1073.76+fips1
- ubuntu•linux-bluefield
all
- ubuntu•linux-fips
< 4.4.0-1049.55 | all | < 4.15.0-1045.52
- ubuntu•linux-gcp
< 4.15.0-1087.100~16.04.1 | all | < 5.4.0-1029.31
- ubuntu•linux-gcp-4.15
< 4.15.0-1087.100
- ubuntu•linux-gcp-5.3
all
- ubuntu•linux-gcp-5.4
< 5.4.0-1029.31~18.04.1
- ubuntu•linux-gcp-edge
all
- ubuntu•linux-gcp-fips
all | < 5.4.0-1067.71~20.04.1
- ubuntu•linux-gke
all
- ubuntu•linux-gke-4.15
< 4.15.0-1073.78
- ubuntu•linux-gke-5.0
< 5.0.0-1050.52
- ubuntu•linux-gke-5.3
< 5.3.0-1039.42
- ubuntu•linux-hwe
< 4.15.0-123.126~16.04.1 | < 5.3.0-69.65
- ubuntu•linux-hwe-5.4
< 5.4.0-53.59~18.04.1
- ubuntu•linux-hwe-5.8
< 5.8.0-28.30~20.04.1
- ubuntu•linux-hwe-edge
all | all
- ubuntu•linux-intel-iot-realtime
all
- ubuntu•linux-lts-xenial
< 4.4.0-194.226~14.04.1
- ubuntu•linux-oem
< 4.15.0-1101.112
- ubuntu•linux-oem-5.6
< 5.6.0-1033.35
- ubuntu•linux-oem-osp1
< 5.0.0-1071.77
- ubuntu•linux-oracle
< 4.15.0-1058.64~16.04.1 | < 4.15.0-1058.64 | < 5.4.0-1029.31
- ubuntu•linux-oracle-5.0
all
- ubuntu•linux-oracle-5.3
all
- ubuntu•linux-oracle-5.4
< 5.4.0-1029.31~18.04.1
- ubuntu•linux-raspi-realtime
all
- ubuntu•linux-raspi2
all
- ubuntu•linux-realtime
all
- ubuntu•linux-riscv
all
- intel•celeron_3855u_firmware
na
- intel•celeron_3865u_firmware
na
- intel•celeron_3955u_firmware
na
- intel•celeron_3965u_firmware
na
- intel•celeron_3965y_firmware
na
- intel•celeron_g3900_firmware
na
- intel•celeron_g3900e_firmware
na
- intel•celeron_g3900t_firmware
na
- intel•celeron_g3900te_firmware
na
Showing first 50 affected entries in server-rendered view.
References (13)
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00389
- https://lists.debian.org/debian-lts-announce/2020/12/msg00015.html
- https://lists.debian.org/debian-lts-announce/2020/12/msg00027.html
- https://cert-portal.siemens.com/productcert/pdf/ssa-678983.pdf
- https://security.alpinelinux.org/vuln/CVE-2020-8694
- https://ubuntu.com/security/CVE-2020-8694
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00389.html
- https://platypusattack.com/
- https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/Platypus
- https://ubuntu.com/security/notices/USN-4626-1
- https://ubuntu.com/security/notices/USN-4627-1
- https://www.cve.org/CVERecord?id=CVE-2020-8694
- https://security-tracker.debian.org/tracker/CVE-2020-8694