Vulnerability Name:

CVE-2020-8832 (CCN-180041)

Assigned:2020-02-11
Published:2020-02-11
Updated:2022-10-11
Summary:The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-200
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2020-8832

Source: CCN
Type: Launchpad Bug #1862840
[Bionic] i915 incomplete fix for CVE-2019-14615

Source: MISC
Type: Issue Tracking, Third Party Advisory
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1862840

Source: XF
Type: UNKNOWN
linux-kernel-cve20208832-info-disc(180041)

Source: CONFIRM
Type: Third Party Advisory
https://security.netapp.com/advisory/ntap-20200430-0004/

Source: CCN
Type: ubuntu Web site
An independent evaluation of Ubuntu Core’s security capabilities

Source: UBUNTU
Type: Third Party Advisory
USN-4302-1

Source: CCN
Type: IBM Security Bulletin 6260205 (Netezza Host Management)
Publicly disclosed vulnerability from Kernel affects IBM Netezza Host Management

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2020-8832

Vulnerable Configuration:Configuration 1:
  • cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*

  • Configuration 2:
  • cpe:/a:netapp:cloud_backup:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:*
  • OR cpe:/a:netapp:solidfire_&_hci_management_node:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:netapp:aff_8300_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_8300:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:netapp:aff_8700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_8700:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:netapp:aff_a220_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a220:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:netapp:aff_a320_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a320:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:netapp:aff_a400_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a400:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:netapp:aff_a700s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_a700s:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:netapp:aff_c190_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:aff_c190:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:netapp:baseboard_management_controller_h300e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h300e:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:netapp:baseboard_management_controller_h300s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h300s:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:netapp:baseboard_management_controller_h410c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h410c:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:netapp:baseboard_management_controller_h410s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h410s:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:netapp:baseboard_management_controller_h500e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h500e:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:netapp:baseboard_management_controller_h500s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h500s:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:netapp:baseboard_management_controller_h610c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h610c:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:netapp:baseboard_management_controller_h610s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h610s:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:netapp:baseboard_management_controller_h615c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h615c:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:netapp:baseboard_management_controller_h700e_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h700e:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:netapp:baseboard_management_controller_h700s_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:baseboard_management_controller_h700s:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:netapp:fas2720_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas2720:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:netapp:fas2750_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas2750:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:netapp:fas8300_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas8300:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:netapp:fas8700_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas8700:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:netapp:fas_baseboard_management_controller_a220_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas_baseboard_management_controller_a220:-:*:*:*:*:*:*:*

  • Configuration 26:
  • cpe:/o:netapp:fas_baseboard_management_controller_a320_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas_baseboard_management_controller_a320:-:*:*:*:*:*:*:*

  • Configuration 27:
  • cpe:/o:netapp:fas_baseboard_management_controller_a400_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas_baseboard_management_controller_a400:-:*:*:*:*:*:*:*

  • Configuration 28:
  • cpe:/o:netapp:fas_baseboard_management_controller_a800_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas_baseboard_management_controller_a800:-:*:*:*:*:*:*:*

  • Configuration 29:
  • cpe:/o:netapp:fas_baseboard_management_controller_c190_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:fas_baseboard_management_controller_c190:-:*:*:*:*:*:*:*

  • Configuration 30:
  • cpe:/o:netapp:solidfire_baseboard_management_controller_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:netapp:solidfire_baseboard_management_controller:-:*:*:*:*:*:*:*

  • Configuration 31:
  • cpe:/o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
  • OR cpe:/o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:4.15.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:com.ubuntu.bionic:def:202088320000000
    V
    CVE-2020-8832 on Ubuntu 18.04 LTS (bionic) - medium.
    2020-03-05
    oval:com.ubuntu.xenial:def:202088320000000
    V
    CVE-2020-8832 on Ubuntu 16.04 LTS (xenial) - medium.
    2020-03-05
    BACK
    canonical ubuntu linux 18.04
    netapp cloud backup -
    netapp steelstore cloud integrated storage -
    netapp solidfire & hci management node -
    netapp aff 8300 firmware -
    netapp aff 8300 -
    netapp aff 8700 firmware -
    netapp aff 8700 -
    netapp aff a220 firmware -
    netapp aff a220 -
    netapp aff a320 firmware -
    netapp aff a320 -
    netapp aff a400 firmware -
    netapp aff a400 -
    netapp aff a700s firmware -
    netapp aff a700s -
    netapp aff c190 firmware -
    netapp aff c190 -
    netapp baseboard management controller h300e firmware -
    netapp baseboard management controller h300e -
    netapp baseboard management controller h300s firmware -
    netapp baseboard management controller h300s -
    netapp baseboard management controller h410c firmware -
    netapp baseboard management controller h410c -
    netapp baseboard management controller h410s firmware -
    netapp baseboard management controller h410s -
    netapp baseboard management controller h500e firmware -
    netapp baseboard management controller h500e -
    netapp baseboard management controller h500s firmware -
    netapp baseboard management controller h500s -
    netapp baseboard management controller h610c firmware -
    netapp baseboard management controller h610c -
    netapp baseboard management controller h610s firmware -
    netapp baseboard management controller h610s -
    netapp baseboard management controller h615c firmware -
    netapp baseboard management controller h615c -
    netapp baseboard management controller h700e firmware -
    netapp baseboard management controller h700e -
    netapp baseboard management controller h700s firmware -
    netapp baseboard management controller h700s -
    netapp fas2720 firmware -
    netapp fas2720 -
    netapp fas2750 firmware -
    netapp fas2750 -
    netapp fas8300 firmware -
    netapp fas8300 -
    netapp fas8700 firmware -
    netapp fas8700 -
    netapp fas baseboard management controller a220 firmware -
    netapp fas baseboard management controller a220 -
    netapp fas baseboard management controller a320 firmware -
    netapp fas baseboard management controller a320 -
    netapp fas baseboard management controller a400 firmware -
    netapp fas baseboard management controller a400 -
    netapp fas baseboard management controller a800 firmware -
    netapp fas baseboard management controller a800 -
    netapp fas baseboard management controller c190 firmware -
    netapp fas baseboard management controller c190 -
    netapp solidfire baseboard management controller firmware -
    netapp solidfire baseboard management controller -
    canonical ubuntu linux 18.04
    canonical ubuntu linux 14.04
    canonical ubuntu linux 16.04
    linux linux kernel 4.15.0