Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-11085

Опубликовано: 14 мая 2019
Источник: redhat
CVSS3: 8.8

Описание

Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

A flaw was found in the Linux kernel's implementation of GVT-g which allowed an attacker with access to a 'passed through' Intel i915 graphics card to possibly access resources allocated to other virtual machines, crash the host, or possibly corrupt memory leading to privilege escalation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernel-altAffected
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2019:189129.07.2019
Red Hat Enterprise Linux 7kernelFixedRHSA-2019:187329.07.2019
Red Hat Enterprise Linux 7.4 Advanced Update SupportkernelFixedRHSA-2020:059225.02.2020
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportkernelFixedRHSA-2020:059225.02.2020
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionskernelFixedRHSA-2020:059225.02.2020
Red Hat Enterprise Linux 7.5 Extended Update SupportkernelFixedRHSA-2020:054319.02.2020
Red Hat Enterprise Linux 8kernel-rtFixedRHSA-2019:197130.07.2019

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-20->CWE-250
https://bugzilla.redhat.com/show_bug.cgi?id=1710405kernel: insufficient input validation in kernel mode driver in Intel i915 graphics leads to privilege escalation

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
около 6 лет назад

Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
nvd
около 6 лет назад

Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
debian
около 6 лет назад

Insufficient input validation in Kernel Mode Driver in Intel(R) i915 G ...

CVSS3: 7.8
github
около 3 лет назад

Insufficient input validation in Kernel Mode Driver in Intel(R) i915 Graphics for Linux before version 5.0 may allow an authenticated user to potentially enable escalation of privilege via local access.

CVSS3: 7.8
fstec
больше 6 лет назад

Уязвимость драйвера графических систем Intel Graphics Kernel Mode Driver процессоров Intel i915, позволяющая нарушителю повысить свои привилегии

8.8 High

CVSS3