Lucene search

K
freebsdFreeBSDD2C2C815-3793-11EA-8BE3-54E1AD3D6335
HistoryJan 14, 2020 - 12:00 a.m.

drm graphics drivers -- potential information disclusure via local access

2020-01-1400:00:00
vuxml.freebsd.org
52

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

41.5%

Intel reports:

.A potential security vulnerability in IntelĀ® Processor Graphics
may allow information disclosure. Intel is releasing software
updates to mitigate this potential vulnerability.
Description: Insufficient control flow in certain data
structures for some IntelĀ® Processors with IntelĀ® Processor
Graphics may allow an unauthenticated user to potentially enable
information disclosure via local access.
This patch provides mitigation for Gen9 hardware only. Patches
for Gen7 and Gen7.5 will be provided later. Note that Gen8 is not
impacted due to a previously implemented workaround. The mitigation
involves using an existing hardware feature to forcibly clear down
all EU state at each context switch.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchdrm-fbsd11.2-kmod<Ā 4.11.g20200115UNKNOWN
FreeBSDanynoarchdrm-fbsd12.0-kmod<Ā 4.16.g20200115UNKNOWN
FreeBSDanynoarchdrm-current-kmod<Ā 4.16.g20200115UNKNOWN
FreeBSDanynoarchdrm-devel-kmod<Ā 5.0.g20200115UNKNOWN

CVSS2

1.9

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

EPSS

0.001

Percentile

41.5%