Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-12362

Опубликовано: 17 фев. 2021
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.

A flaw was found in the Linux kernel. An integer overflow in the firmware for some Intel(R) Graphics Drivers may allow a privileged user to potentially enable an escalation of privilege via local access. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.

Отчет

Only users that specify i915.enable_guc=-1 or i915.enable_guc=1 or 2 are open to be exploited by this issue. Due to the full fix (combination of kernel and firmware updates) being invasive and GUC firmware loading is off by default, Red Hat Enterprise Linux kernel versions prior to the Linux kernel version shipped with Red Hat Enterprise Linux 8.4 GA (kernel-4.18.0-305.el8) print a warning in the kernel log ("GUC firmware is insecure - CVE 2020-12362 - Please update to a newer release to get secure GUC") and do not rely on the firmware fix. As a result, Red Hat Enterprise Linux versions prior Red Hat Enterprise Linux 8.4 GA (including Red Hat Enterprise Linux 6 and 7) do not include the updated firmware packages.

Меры по смягчению последствий

Red Hat has investigated whether a possible mitigation exists for this issue, and has not been able to identify a practical example.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7linux-firmwareWill not fix
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9linux-firmwareNot affected
Red Hat Enterprise Linux 6 Extended Lifecycle SupportkernelFixedRHSA-2021:273520.07.2021
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2021:231608.06.2021
Red Hat Enterprise Linux 7kernelFixedRHSA-2021:231408.06.2021
Red Hat Enterprise Linux 7.3 Advanced Update SupportkernelFixedRHSA-2021:229308.06.2021
Red Hat Enterprise Linux 7.4 Advanced Update SupportkernelFixedRHSA-2021:216401.06.2021
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportkernelFixedRHSA-2021:216401.06.2021

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=1930246kernel: Integer overflow in Intel(R) Graphics Drivers

EPSS

Процентиль: 32%
0.00117
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 4 лет назад

Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVSS3: 7.8
nvd
больше 4 лет назад

Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVSS3: 7.8
debian
больше 4 лет назад

Integer overflow in the firmware for some Intel(R) Graphics Drivers fo ...

CVSS3: 7.8
github
около 3 лет назад

Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access.

CVSS3: 7.8
fstec
больше 4 лет назад

Уязвимость драйвера графических систем Intel Graphics Drivers для Windows, вызванная целочисленным переполнением, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 32%
0.00117
Низкий

7.8 High

CVSS3

Уязвимость CVE-2020-12362