CVE-2020-8832Missing XML Validation in 18.04 LTS Linux Kernel

Severity
5.5MEDIUMNVD
EPSS
0.3%
top 45.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 10
Latest updateNov 21

Description

The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5ubuntu/18.04_lts_linux_kernel4.15.x kernels4.15.0-91.92
Debianlinux/linux_kernel< 4.16.5-1+3
Ubuntulinux/linux_kernel< 4.15.0-91.92

Also affects: Ubuntu Linux 14.04, 16.04, 18.04

🔴Vulnerability Details

4
GHSA
GHSA-xqc2-q3vp-2m56: The fix for the Linux kernel in Ubuntu 182022-05-24
OSV
CVE-2020-8832: The fix for the Linux kernel in Ubuntu 182020-04-10
CVEList
Ubuntu 18.04 Linux kernel i915 incomplete fix for CVE-2019-146152020-04-09
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities2020-03-25

📋Vendor Advisories

3
Red Hat
kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure2020-03-25
Ubuntu
Linux kernel vulnerabilities2020-03-25
Debian
CVE-2020-8832: linux - The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux ...2020

📄Research Papers

1
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel2025-11-21

💬Community

2
Bugzilla
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure [fedora-all]2020-03-25
Bugzilla
CVE-2020-8832 kernel: incomplete fix for CVE-2019-14615 allows for a local information exposure2020-03-25
CVE-2020-8832 — Missing XML Validation | cvebase