Lucene search

K
ubuntucveUbuntu.comUB:CVE-2020-12364
HistoryFeb 17, 2021 - 12:00 a.m.

CVE-2020-12364

2021-02-1700:00:00
ubuntu.com
ubuntu.com
19
null pointer reference
intel graphics drivers
windows
linux
denial of service
firmware update
kernel patch

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

12.6%

Null pointer reference in some Intelยฎ Graphics Drivers for Windows*
before version 26.20.100.7212 and before version Linux kernel version 5.5
may allow a privileged user to potentially enable a denial of service via
local access.

Notes

Author Note
mdeslaur per Intel, this was fixed by a firmware update. v49.0.1 of the firmware is required. The new firmware requires a kernel patch: c784e5249e773689e38d2bc1749f08b986621a26

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:L/AC:L/Au:N/C:N/I:N/A:P

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS

0

Percentile

12.6%