SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-8832

The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the…

MEDIUM 5.5EPSS 0.45%

Does this matter?

Lower severity and a low EPSS score (0.45%). Track it; it rarely justifies an emergency change on its own.

Description

The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS
0.45% probability · 38th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
canonical/ubuntu linux · netapp/cloud backup · netapp/solidfire \& hci management node · netapp/steelstore cloud integrated storage · netapp/aff 8300 firmware · netapp/aff 8700 firmware · netapp/aff a220 firmware · netapp/aff a320 firmware · netapp/aff a400 firmware · netapp/aff a700s firmware · netapp/aff c190 firmware · netapp/h300e firmware · netapp/h300s firmware · netapp/h410c firmware · netapp/h410s firmware · netapp/h500e firmware · netapp/h500s firmware · netapp/h610c firmware · netapp/h610s firmware · netapp/h615c firmware · +12 more
Source
security@ubuntu.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.