Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2020-8694

Опубликовано: 10 нояб. 2020
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

A flaw was found in the Linux kernel's implementation of Intel's Running Average Power Limit (RAPL) implementation. A local attacker could infer secrets by measuring power usage and also infer private data by observing the power usage of calculations performed on the data.

Меры по смягчению последствий

A temporary measure would be to remove the ability for non-root users to read the current RAPL energy reporting metrics. This can be done with the command: $ sudo chmod 400 /sys/class/powercap/intel_rapl/*/energy_uj This mitigation will only work on the current boot and will need to be reapplied at each system boot to remain in effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelWill not fix
Red Hat Enterprise Linux 7kernel-altNot affected
Red Hat Enterprise Linux 7kernel-rtWill not fix
Red Hat Enterprise Linux 7microcode_ctlNot affected
Red Hat Enterprise Linux 8kernelWill not fix
Red Hat Enterprise Linux 8kernel-rtWill not fix
Red Hat Enterprise Linux 8microcode_ctlNot affected
Red Hat Enterprise MRG 2kernel-rtWill not fix

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-284->CWE-200
https://bugzilla.redhat.com/show_bug.cgi?id=1828580kernel: Insufficient access control vulnerability in PowerCap Framework

EPSS

Процентиль: 76%
0.00991
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 4 лет назад

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
nvd
больше 4 лет назад

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
debian
больше 4 лет назад

Insufficient access control in the Linux kernel driver for some Intel( ...

github
около 3 лет назад

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.

CVSS3: 5.5
fstec
больше 4 лет назад

Уязвимость драйвера для процессоров Intel(R) ядра операционной системы Linux, связанная с недостатками контроля доступа, позволяющая нарушителю получить доступ к конфиденциальным данным

EPSS

Процентиль: 76%
0.00991
Низкий

5.5 Medium

CVSS3