CVE-2019-14615

Severity
5.5MEDIUM
EPSS
4.5%
top 10.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 17
Latest updateMay 24

Description

Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages25 packages

CVEListV5intel/intel(r)_processorsvarious
NVDintel/celeron4 versions+3
NVDintel/celeron_j10 versions+9
NVDintel/celeron_n23 versions+22
CVEListV5ubuntu/18.04_lts_(bionic)_linux_kernel4.15.x kernels4.15.0-91.92

Also affects: Ubuntu Linux 14.04, 16.04, 18.04, 19.10

🔴Vulnerability Details

16
GHSA
GHSA-pv73-c93j-h78m: Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user t2022-05-24
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities2020-03-25
OSV
linux, linux-aws, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-raspi2-5.3 vulnerabilities2020-02-19
OSV
linux, linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities2020-02-18
OSV
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities2020-02-18

📋Vendor Advisories

15
Red Hat
kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure2020-03-25
Ubuntu
Linux kernel vulnerabilities2020-02-19
Ubuntu
Linux kernel vulnerabilities2020-02-18
Ubuntu
Linux kernel vulnerabilities2020-02-18
Ubuntu
Linux kernel (Azure) vulnerabilities2020-02-18

💬Community

4
Bugzilla
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure [fedora-all]2020-03-25
Bugzilla
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure2020-03-25
Bugzilla
CVE-2019-14615 kernel: Intel graphics card information leak. [fedora-all]2020-01-20
Bugzilla
CVE-2019-14615 kernel: Intel graphics card information leak.2020-01-09
CVE-2019-14615 (MEDIUM CVSS 5.5) | Insufficient control flow in certai | cvebase.io