Information disclosure in Linux kernel - CVE-2019-14615

 

Information disclosure in Linux kernel - CVE-2019-14615

Published: January 17, 2020 / Updated: June 1, 2020


Vulnerability identifier: #VU28407
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-14615
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: Linux Foundation
Affected software:
Linux kernel

Detailed vulnerability description

The vulnerability allows a local non-authenticated attacker to gain access to sensitive information.

Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.


How to mitigate CVE-2019-14615

Install update from vendor's website.

Sources