CVE-2019-0154Improper Access Control in Intel Atom X5-a3930 Firmware

Severity
5.5MEDIUMNVD
OSV6.5
EPSS
0.1%
top 73.48%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14
Latest updateMay 24

Description

Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families may allow an authenticated user to potentially enable denial of service via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages150 packages

NVDintel/xeon_e-2124_firmware< 26.20.100.6859
NVDintel/xeon_e-2134_firmware< 26.20.100.6859
NVDintel/xeon_e-2136_firmware< 26.20.100.6859

Also affects: Ubuntu Linux 14.04

🔴Vulnerability Details

9
GHSA
GHSA-wxww-q7fc-j26f: Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; In2022-05-24
OSV
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; In2019-11-14
OSV
linux, linux-aws, linux-kvm vulnerabilities2019-11-13
OSV
linux vulnerability2019-11-13
OSV
linux-lts-xenial, linux-aws vulnerabilities2019-11-13

📋Vendor Advisories

11
Ubuntu
Linux kernel vulnerabilities2019-11-13
Ubuntu
Linux kernel vulnerability and regression2019-11-13
Ubuntu
Linux kernel vulnerabilities2019-11-13
Ubuntu
Linux kernel vulnerability and regression2019-11-13
Ubuntu
Linux kernel vulnerabilities2019-11-13

💬Community

2
Bugzilla
CVE-2019-0154 kernel: hw: Intel GPU Denial Of Service while accessing MMIO in lower power state [fedora-all]2019-11-12
Bugzilla
CVE-2019-0154 hw: Intel GPU Denial Of Service while accessing MMIO in lower power state2019-06-27