CVE-2020-8695
published 2020-11-12CVE-2020-8695: Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.41%
33.9th percentile
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | intel-microcode | < intel-microcode 3.20201110.1 (bookworm) | intel-microcode 3.20201110.1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| github.com | containerd_containerd | >= 0 < 1.6.26 | 1.6.26 |
| github.com | containerd_containerd | >= 1.7.0 < 1.7.11 | 1.7.11 |
| github.com | docker_docker | >= 0 < 20.10.27 | 20.10.27 |
| github.com | docker_docker | >= 21.0.0 < 23.0.8 | 23.0.8 |
| github.com | docker_docker | >= 24.0.0 < 24.0.7 | 24.0.7 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
ghsa5.5MEDIUM
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
containerd allows RAPL to be accessible to a container
osv·2023-12-19·CVSS 5.5
[MEDIUM] containerd allows RAPL to be accessible to a container
containerd allows RAPL to be accessible to a container
# /sys/devices/virtual/powercap accessible by default to containers
Intel's RAPL (Running Average Power Limit) feature, introduced by the Sandy Bridge microarchitecture, provides software insights into hardware energy consumption. To facilitate this, Intel introduced the powercap framework in Linux kernel 3.13, which reads values via relevant MSRs (model specific registers) and provides unprivileged userspace access via `sysfs`. As RAPL is an interface to access a hardware feature, it is only available when running on bare metal with the module compiled into the kernel.
By 2019, it was realized that in some cases unprivileged access to RAPL readings could be exploited as a power-based side-channel against security features including
GHSA
containerd allows RAPL to be accessible to a container
ghsa·2023-12-19·CVSS 5.5
[MEDIUM] containerd allows RAPL to be accessible to a container
containerd allows RAPL to be accessible to a container
# /sys/devices/virtual/powercap accessible by default to containers
Intel's RAPL (Running Average Power Limit) feature, introduced by the Sandy Bridge microarchitecture, provides software insights into hardware energy consumption. To facilitate this, Intel introduced the powercap framework in Linux kernel 3.13, which reads values via relevant MSRs (model specific registers) and provides unprivileged userspace access via `sysfs`. As RAPL is an interface to access a hardware feature, it is only available when running on bare metal with the module compiled into the kernel.
By 2019, it was realized that in some cases unprivileged access to RAPL readings could be exploited as a power-based side-channel against security features including
GHSA
/sys/devices/virtual/powercap accessible by default to containers
ghsa·2023-10-30·CVSS 5.5
[MEDIUM] /sys/devices/virtual/powercap accessible by default to containers
/sys/devices/virtual/powercap accessible by default to containers
Intel's RAPL (Running Average Power Limit) feature, introduced by the Sandy Bridge microarchitecture, provides software insights into hardware energy consumption. To facilitate this, Intel introduced the powercap framework in Linux kernel 3.13, which reads values via relevant MSRs (model specific registers) and provides unprivileged userspace access via `sysfs`. As RAPL is an interface to access a hardware feature, it is only available when running on bare metal with the module compiled into the kernel.
By 2019, it was realized that in some cases unprivileged access to RAPL readings could be exploited as a power-based side-channel against security features including AES-NI (potentially inside a SGX enclave) and KASLR (kern
OSV
/sys/devices/virtual/powercap accessible by default to containers
osv·2023-10-30·CVSS 5.5
[MEDIUM] /sys/devices/virtual/powercap accessible by default to containers
/sys/devices/virtual/powercap accessible by default to containers
Intel's RAPL (Running Average Power Limit) feature, introduced by the Sandy Bridge microarchitecture, provides software insights into hardware energy consumption. To facilitate this, Intel introduced the powercap framework in Linux kernel 3.13, which reads values via relevant MSRs (model specific registers) and provides unprivileged userspace access via `sysfs`. As RAPL is an interface to access a hardware feature, it is only available when running on bare metal with the module compiled into the kernel.
By 2019, it was realized that in some cases unprivileged access to RAPL readings could be exploited as a power-based side-channel against security features including AES-NI (potentially inside a SGX enclave) and KASLR (kern
GHSA
GHSA-55fx-92rr-h42r: Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via
ghsa_unreviewed·2022-05-24
CVE-2020-8695 [MEDIUM] GHSA-55fx-92rr-h42r: Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
OSV
intel-microcode vulnerabilities
osv·2021-05-17·CVSS 5.5
[MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
USN-4628-1 provided updated Intel Processor Microcode for various processor
types. This update provides the corresponding updates for some additional
processor types.
Original advisory details:
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use this to expose sensitive information. (CVE-2020-8695)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly remove sensitive information
before storage or transfer in some situations. A local atta
OSV
CVE-2020-8695: Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via
osv·2020-11-12·CVSS 5.5
CVE-2020-8695 [MEDIUM] CVE-2020-8695: Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
OSV
intel-microcode regression
osv·2020-11-12·CVSS 5.5
[MEDIUM] intel-microcode regression
intel-microcode regression
USN-4628-1 provided updated Intel Processor Microcode. Unfortunately,
that update prevented certain processors in the Intel Tiger Lake family
from booting successfully. This update reverts the microcode update for
the Tiger Lake processor family.
Please note that the 'dis_ucode_ldr' kernel command line option can be
added in the boot menu to disable microcode loading for system recovery.
We apologize for the inconvenience.
Original advisory details:
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use
OSV
intel-microcode vulnerabilities
osv·2020-11-11·CVSS 5.5
CVE-2020-8695 [MEDIUM] intel-microcode vulnerabilities
intel-microcode vulnerabilities
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use this to expose sensitive information. (CVE-2020-8695)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly remove sensitive information
before storage or transfer in some situations. A local attacker could
possibly use this to expose sensitive information. (CVE-2020-8696)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly iso
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2021-05-17·CVSS 5.5
CVE-2020-8698 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
USN-4628-1 provided updated Intel Processor Microcode for various processor
types. This update provides the corresponding updates for some additional
processor types.
Original advisory details:
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use this to expose sensitive information. (CVE-2020-8695)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly remove sensitive
Ubuntu
Intel Microcode regression
vendor_ubuntu·2020-11-12·CVSS 5.5
[MEDIUM] Intel Microcode regression
Title: Intel Microcode regression
Summary: USN-4628-1 introduced a regression in the Intel Microcode for some processors.
USN-4628-1 provided updated Intel Processor Microcode. Unfortunately,
that update prevented certain processors in the Intel Tiger Lake family
from booting successfully. This update reverts the microcode update for
the Tiger Lake processor family.
Please note that the 'dis_ucode_ldr' kernel command line option can be
added in the boot menu to disable microcode loading for system recovery.
We apologize for the inconvenience.
Original advisory details:
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a si
Ubuntu
Intel Microcode vulnerabilities
vendor_ubuntu·2020-11-11·CVSS 5.5
CVE-2020-8698 [MEDIUM] Intel Microcode vulnerabilities
Title: Intel Microcode vulnerabilities
Summary: Several security issues were fixed in Intel Microcode.
Moritz Lipp, Michael Schwarz, Andreas Kogler, David Oswald, Catherine
Easdon, Claudio Canella, and Daniel Gruss discovered that the Intel Running
Average Power Limit (RAPL) feature of some Intel processors allowed a side-
channel attack based on power consumption measurements. A local attacker
could possibly use this to expose sensitive information. (CVE-2020-8695)
Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered that
some Intel(R) Processors did not properly remove sensitive information
before storage or transfer in some situations. A local attacker could
possibly use this to expose sensitive information. (CVE-2020-8696)
Ezra Caltum, Joseph Nuzman, Nir Shildan and O
Red Hat
hw: Information disclosure issue in Intel SGX via RAPL interface
vendor_redhat·2020-11-10·CVSS 5.5
CVE-2020-8695 [MEDIUM] CWE-200 hw: Information disclosure issue in Intel SGX via RAPL interface
hw: Information disclosure issue in Intel SGX via RAPL interface
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
A vulnerability was found in Intel's implementation of RAPL (Running Average Power Limit). An attacker with a local account could query the power management functionality to intelligently infer SGX enclave computation values by measuring power usage in the RAPL subsystem.
Mitigation: Until a firmware update and reboot can be applied, the attack vector can be reduced by limiting read access to the sysfs attributes that export this functionality to userspace.
The command:
~~~
sudo chmod 400 /sys/class/powercap/intel_rapl/*/energy_uj
~~~
Will do this for the curre
Debian
CVE-2020-8695: intel-microcode - Observable discrepancy in the RAPL interface for some Intel(R) Processors may al...
vendor_debian·2020·CVSS 5.5
CVE-2020-8695 [MEDIUM] CVE-2020-8695: intel-microcode - Observable discrepancy in the RAPL interface for some Intel(R) Processors may al...
Observable discrepancy in the RAPL interface for some Intel(R) Processors may allow a privileged user to potentially enable information disclosure via local access.
Scope: local
bookworm: resolved (fixed in 3.20201110.1)
bullseye: resolved (fixed in 3.20201110.1)
forky: resolved (fixed in 3.20201110.1)
sid: resolved (fixed in 3.20201110.1)
trixie: resolved (fixed in 3.20201110.1)
No detection rules found.
No public exploits indexed.
arXiv
DeepTheft: Stealing DNN Model Architectures through Power Side Channel
arxiv_fulltext·2023-09-21
DeepTheft: Stealing DNN Model Architectures through Power Side Channel
: Stealing DNN Model Architectures through Power Side Channel
Yansong Gao1, Huming Qiu2, Zhi Zhang3, Binghui Wang4,
Hua Ma5, Alsharif Abuadbba1, Minhui Xue1, Anmin Fu6, Surya Nepal1
1CSIRO's Data61 2Fudan University 3The University of Western Australia
4Illinois Institute of Technology 6Nanjing University of Science and Technology 5The University of Adelaide
Yansong Gao. Email: [email protected]
Zhi Zhang is the corresponding author. Email: [email protected]
firstpage
## Abstract
Deep Neural Network (DNN) models are often deployed in resource-sharing clouds as Machine Learning as a Service (MLaaS) to provide inference services.
To steal model architectures that are of valuable intellectual properties, a class of attacks has been proposed via different side-channel leakage,
Bugzilla
CVE-2020-8695 hw: Information disclosure issue in Intel SGX via RAPL interface
bugzilla·2020-04-27·CVSS 5.5
CVE-2020-8695 [MEDIUM] CVE-2020-8695 hw: Information disclosure issue in Intel SGX via RAPL interface
CVE-2020-8695 hw: Information disclosure issue in Intel SGX via RAPL interface
A vulnerability was found in Intel's implementation of RAPL (Running Average Power Limit). An attacker with a local account could query the power management functionality to intelligently infer SGX enclave computation values by measuring power usage in the RAPL subsystem.
This creates a 'power analysis' side channel, where the attacker can use the RAPL values exported to the operating system as a method to analyse the side channel without physical access.
Discussion:
Acknowledgments:
Name: Intel
---
External References:
https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00389.html
https://en.wikipedia.org/wiki/Power_analysis
---
This issue has been addressed in the following prod
CWE
Improper Restriction of Software Interfaces to Hardware Features
mitre_cwe
CWE-1256 Improper Restriction of Software Interfaces to Hardware Features
CWE-1256: Improper Restriction of Software Interfaces to Hardware Features
The product provides software-controllable
device functionality for capabilities such as power and
clock management, but it does not properly limit
functionality that can lead to modification of
hardware memory or register bits, or the ability to
observe physical side channels.
It is frequently assumed that physical attacks
such as fault injection and side-channel analysis
require an attacker to have physical access to the
target device. This assumption may be false if the
device has improperly secured power management features,
or similar features. For mobile devices, minimizing
power consumption is critical, but these devices run a
wide variety of applications with different performance
requirements. Software-co
CWE
Observable Discrepancy
mitre_cwe
CWE-203 Observable Discrepancy
CWE-203: Observable Discrepancy
The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor, which exposes security-relevant information about the state of the product, such as whether a particular operation was successful or not.
Discrepancies can take many forms, and variations may be detectable in timing, control flow, communications such as replies or requests, or general behavior. These discrepancies can reveal information about the product's operation or internal state to an unauthorized actor. In some cases, discrepancies can be used by attackers to form a side channel.
Modes of Introduction:
Phase: Architecture and Design
Phase: Implementation
Common Consequences:
Scope: Confidentiality, Access
https://lists.debian.org/debian-lts-announce/2021/02/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQ24MFBVH3HJW3PNRQBRY4YXKC7GA57W/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GRFC7UAPKAFFH5WX3AMDUBVHLKYQA2NZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MAAGIK5CXKBPGY3R4UR5VO56M7MKLZ43/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEM2FZWVE4FNGYNQU3WCBAWTZRBWDYUR/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00389https://lists.debian.org/debian-lts-announce/2021/02/msg00007.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/AQ24MFBVH3HJW3PNRQBRY4YXKC7GA57W/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GRFC7UAPKAFFH5WX3AMDUBVHLKYQA2NZ/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MAAGIK5CXKBPGY3R4UR5VO56M7MKLZ43/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NEM2FZWVE4FNGYNQU3WCBAWTZRBWDYUR/https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00389
2020-11-12
Published