CVE-2019-8832
published 2020-10-27CVE-2019-8832: A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.30%
67.2th percentile
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with system privileges.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | ios_13.3_and_ipados | — | — |
| apple | ios_and_ipados | >= unspecified < 13.3 | 13.3 |
| apple | ipados | < 13.3 | 13.3 |
| apple | iphone_os | < 13.3 | 13.3 |
| apple | mac_os_x | < 10.15.2 | 10.15.2 |
| apple | macos | >= unspecified < 10.15 | 10.15 |
| apple | macos | >= unspecified < 6.1 | 6.1 |
| apple | macos | >= unspecified < 13.3 | 13.3 |
| apple | macos_catalina_10.15.2_security_update_2019-002_mojave_security_update_2019-007 | — | — |
| apple | tvos | < 13.3 | 13.3 |
| apple | tvos | — | — |
| apple | watchos | < 6.1.1 | 6.1.1 |
| apple | watchos | — | — |
| linux | linux_kernel | >= 0 < 4.15.0-91.92 | 4.15.0-91.92 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-hrj2-j6cf-8992: A memory corruption issue was addressed with improved memory handling
ghsa_unreviewed·2022-05-24
CVE-2019-8832 [HIGH] CWE-119 GHSA-hrj2-j6cf-8992: A memory corruption issue was addressed with improved memory handling
A memory corruption issue was addressed with improved memory handling. This issue is fixed in iOS 13.3 and iPadOS 13.3, watchOS 6.1.1, macOS Catalina 10.15.2, Security Update 2019-002 Mojave, and Security Update 2019-007 High Sierra, tvOS 13.3. An application may be able to execute arbitrary code with system privileges.
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities
osv·2020-03-25·CVSS 5.5
CVE-2020-2732 linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities
Paulo Bonzini discovered that the KVM hypervisor implementation in the
Linux kernel could improperly let a nested (level 2) guest access the
resources of a parent (level 1) guest in certain situations. An attacker
could use this to expose sensitive information. (CVE-2020-2732)
Gregory Herrero discovered that the fix for CVE-2019-14615 to address the
Linux kernel not properly clearing data structures on context switches for
certain Intel graphics processors was incomplete. A local attacker could
use this to expose sensitive information. (CVE-2020-8832)
It was discovered that the IPMI message handler implementation in the Li
Red Hat
kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
vendor_redhat·2020-03-25·CVSS 5.5
CVE-2020-8832 [MEDIUM] CWE-112 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.
An information disclosure flaw was found in the Linux kernel. The original fix for CVE-2019-14615 was deemed to be incomplete. The i915 graphics driver lacks control of flow for data structures which may allow a local, authenticated user to disclose information when using ioctl commands with an attached i915 device. The highest threat from this vulnerability i
Apple
CVE-2019-8832: iOS 13.3 and iPadOS 13.3
vendor_apple·2019-12-10·CVSS 7.8
CVE-2019-8832 [HIGH] CVE-2019-8832: iOS 13.3 and iPadOS 13.3
Apple Security Update: About the security content of iOS 13.3 and iPadOS 13.3
Product: iOS 13.3 and iPadOS
Version: 13.3
CVE: CVE-2019-8832
Component: Security
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2019-8832: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
vendor_apple·2019-12-10·CVSS 7.8
CVE-2019-8832 [HIGH] CVE-2019-8832: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Apple Security Update: About the security content of macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
Product: macOS Catalina 10.15.2, Security Update 2019-002 Mojave, Security Update 2019-007 High Sierra
CVE: CVE-2019-8832
Component: Security
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2019-8832: tvOS 13.3
vendor_apple·2019-12-10·CVSS 7.8
CVE-2019-8832 [HIGH] CVE-2019-8832: tvOS 13.3
Apple Security Update: About the security content of tvOS 13.3
Product: tvOS
Version: 13.3
CVE: CVE-2019-8832
Component: Security
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
Apple
CVE-2019-8832: watchOS 6.1.1
vendor_apple·2019-12-10·CVSS 7.8
CVE-2019-8832 [HIGH] CVE-2019-8832: watchOS 6.1.1
Apple Security Update: About the security content of watchOS 6.1.1
Product: watchOS
Version: 6.1.1
CVE: CVE-2019-8832
Component: Security
Impact: An application may be able to execute arbitrary code with system privileges
Description: A memory corruption issue was addressed with improved memory handling.
No detection rules found.
No public exploits indexed.
Sentinelone
macOS Catalina 10.15.2 Update: What's New
blogs_sentinelone·2019-12-12·CVSS 8.8
[HIGH] macOS Catalina 10.15.2 Update: What's New
It’s been two months since Apple dropped the initial release of macOS Catalina, and after a rapid few supplemental updates and a first point upgrade in the first month, things appear to have slowed down to a normal cadence. This week, Apple dropped the public release of 10.15.2, a full month after showing developers the first beta. So, what’s changed in this update? Let’s take a look and see!
## Features and Tweaks
After installing the 10.15.2 update, users should find they are now on build 19C57. While point updates are not typically opportunities for Apple to add new features, 10.15.2 does bring a small number of user level additions.
Apple News receives a new layout and now carries content from the Wall Street Journal and other “leading newspapers”, while Stocks adds links to related
Sentinelone
macOS Catalina 10.15.2 Update: What's New
blogs_sentinelone·2019-12-12·CVSS 8.8
[HIGH] macOS Catalina 10.15.2 Update: What's New
It’s been two months since Apple dropped the initial release of macOS Catalina, and after a rapid few supplemental updates and a first point upgrade in the first month, things appear to have slowed down to a normal cadence. This week, Apple dropped the public release of 10.15.2, a full month after showing developers the first beta. So, what’s changed in this update? Let’s take a look and see!
## Features and Tweaks
After installing the 10.15.2 update, users should find they are now on build 19C57 . While point updates are not typically opportunities for Apple to add new features, 10.15.2 does bring a small number of user level additions.
Apple News receives a new layout and now carries content from the Wall Street Journal and other “leading newspapers”, while Stocks adds links to relate
Bugzilla
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure [fedora-all]
bugzilla·2020-03-25·CVSS 5.5
CVE-2020-8832 [MEDIUM] CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure [fedora-all]
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
bugzilla·2020-03-25·CVSS 5.5
CVE-2020-8832 [MEDIUM] CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure
The fix for CVE-2019-14615 to address the Linux kernel not properly clearing data structures on context switches for certain Intel graphics processors was incomplete. A local attacker could use this to expose sensitive information.
https://lists.ubuntu.com/archives/kernel-team/2020-February/107444.html
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1817048]
---
Mitigation:
Preventing loading of the i915 kernel module will prevent attackers from using this exploit against the system; however, the power management functionality of the card will be disabled and the system may draw additional power. See the kcs “How do I blacklist a kernel module to prevent
https://support.apple.com/en-us/HT210785https://support.apple.com/en-us/HT210788https://support.apple.com/en-us/HT210789https://support.apple.com/en-us/HT210790https://support.apple.com/en-us/HT210785https://support.apple.com/en-us/HT210788https://support.apple.com/en-us/HT210789https://support.apple.com/en-us/HT210790
2020-10-27
Published