Observable Response Discrepancy in Intel products - CVE-2020-8695
Published: November 11, 2020
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to observable discrepancy in the Running Average Power Limit (RAPL) Interface. A local administrator can gain access to sensitive information on the target system.
Affected products:
|
Product Collection |
Vertical Segment |
CPUID |
|
8th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
|
10th Generation Intel® Core™ Processor Family |
Mobile |
806EC |
|
8th Generation Intel® Core™ Processor Family |
Mobile |
906EA |
|
9th Generation Intel® Core™ Processor Family |
Mobile |
906EC |
|
8th Generation Intel® Core™ Processor Family |
Desktop |
906EA |
|
9th Generation Intel® Core™ Processor Family |
Desktop |
906EC |
|
Intel® Xeon® Processor E Family |
Server Workstation AMT Server |
906EA |
|
8th Generation Intel® Core™ Processor Family |
Mobile |
806EA |
|
8th Generation Intel® Core™ Processor Family Intel® Pentium® Gold Processor Series Intel® Celeron® Processor G Series |
Desktop |
906EB |
|
Intel® Xeon® Processor E Family |
Server Workstation AMT Server |
906EA |
|
8th Generation Intel® Core™ Processor Family |
Desktop |
906EA |
|
9th Generation Intel® Core™ Processor Family |
Desktop |
906ED |
|
9th Generation Intel® Core™ Processor Family |
Desktop |
906ED |
|
10th Generation Intel® Core™ Processor Family |
Mobile |
A0660 |
|
10th Generation Intel® Core™ Processor Family |
Mobile |
A0661 |
|
10th Generation Intel® Core™ Processor Family |
Mobile |
806EC |
|
10th Generation Intel® Core™ Processor Family |
Desktop |
A0653 |
|
10th Generation Intel® Core™ Processor Family |
Mobile |
A0655 |
|
10th Generation Intel® Core™ Processor Family |
Mobile |
A0652 |
|
Intel® Pentium® Processor Silver Series Intel® Celeron® Processor J Series Intel® Celeron® Processor N Series |
Desktop Mobile Embedded |
706A1 |
|
Intel® Pentium® Processor Silver Series Intel® Celeron® Processor J Series Intel® Celeron® Processor N Series |
Desktop Mobile Embedded |
706A8 |
|
10th Generation Intel® Core™ Processor Family |
Mobile |
706E5 |
|
8th Generation Intel® Core™ Processor Family |
Mobile |
906E9 |
|
7th Generation Intel® Core™ Processor Family |
Mobile Embedded |
906E9 |
|
8th Generation Intel® Core™ Processor Family |
Mobile |
806EA |
|
7th Generation Intel® Core™ Processor Family |
Desktop Embedded |
906E9 |
|
7th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
|
7th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
|
Intel® Core™ X-series Processors |
Desktop |
906E9 |
|
Intel® Xeon® Processor E3 v6 Family |
Server Workstation AMT Server |
906E9 |
|
7th Generation Intel® Core™ Processor Family |
Mobile |
806E9 |
|
6th Generation Intel® Core™ Processor Family |
Mobile |
506E3 |
|
6th Generation Intel® Core™ Processor Family |
Desktop Embedded |
506E3 |
|
6th Generation Intel® Core™ Processors |
Mobile |
406E3 |
|
6th Generation Intel® Core™ Processor Family |
Mobile |
406E3 |
|
Intel® Xeon® Processor E3 v5 Family |
Server Workstation AMT Server |
506E3 |
|
6th Generation Intel® Core™ Processor Family |
Mobile |
406E3 |
|
8th Generation Intel® Core™ Processors |
Mobile |
806EB |
|
8th Generation Intel® Core™ Processors |
Mobile |
806EC |
Affected software
10th Generation Intel Core Processors
Intel Xeon Processor E Family
Intel Pentium Processor Silver Series
Intel Celeron Processor J Series
Intel Celeron Processor N Series
7th Generation Intel Core Processors
Intel Core X-series Processors
Intel Xeon Processor E3 v6 Family
6th Generation Intel Core Processors
Intel Xeon Processor E3 v5 Family
9th Generation Intel Core Processors
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
CentOS
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Anolis OS
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Fedora
containerd
Data Computing Appliance (DCA)
microcode_ctl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
rootlesskit
rootlesskit-debuginfo
runc
runc-debuginfo
containerd
microcode_ctl
intel-microcode (Ubuntu package)
docker
docker-debuginfo
docker-bash-completion
docker-fish-completion
docker-zsh-completion
docker-rootless-extras
IBM Concert Software
Azure Stack
How to mitigate CVE-2020-8695
microcode_ctl (Red Hat package) - addressed in versions 2.1-12.34.el7_2, 2.1-12.39.el7_2, 2.1-16.37.el7_3, 2.1-16.42.el7_3, 2.1-22.36.el7_4, 2.1-22.41.el7_4, 2.1-47.18.el7_6, 2.1-47.23.el7_6, 2.1-53.13.el7_7, 2.1-53.18.el7_7, 2.1-73.2.el7_9, 2.1-73.11.el7_9, 20180807a-2.20201112.1.el8_0, 20190618-1.20201112.1.el8_1, 20190618-1.20210608.1.el8_1, 20191115-4.20201112.1.el8_2, 20191115-4.20210608.1.el8_2, 20200609-2.20201027.1.el8_3, 20210216-1.20210608.1.el8_4
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
IBM Concert Software - update to 1.0.1
rootlesskit - update to 1.1.1-150000.1.3.3
rootlesskit-debuginfo - update to 1.1.1-150000.1.3.3
runc - update to 1.1.10-16.40.1
runc-debuginfo - update to 1.1.10-16.40.1
containerd - update to 1.7.8-16.88.1
microcode_ctl - addressed in versions 2.1-39.2.fc31, 2.1-39.2.fc32, 2.1-39.3.fc31, 2.1-39.3.fc32, 2.1-42.fc33, 2.1-43.fc33
intel-microcode (Ubuntu package) - addressed in versions 3.20201110.0ubuntu0.16.04.1, 3.20201110.0ubuntu0.16.04.2, 3.20201110.0ubuntu0.18.04.1, 3.20201110.0ubuntu0.18.04.2, 3.20201110.0ubuntu0.20.04.1, 3.20201110.0ubuntu0.20.04.2, 3.20201110.0ubuntu0.20.10.1, 3.20201110.0ubuntu0.20.10.2, 3.20210216.0ubuntu0.18.04.1, 3.20210216.0ubuntu0.20.04.1, 3.20210216.0ubuntu0.20.10.1, 3.20210216.0ubuntu0.21.04.1
Azure Stack - update to 10.2402
docker - addressed in versions 24.0.7_ce-98.103.1, 24.0.7_ce-150000.190.4
docker-debuginfo - addressed in versions 24.0.7_ce-98.103.1, 24.0.7_ce-150000.190.4
docker-bash-completion - update to 24.0.7_ce-150000.190.4
docker-fish-completion - update to 24.0.7_ce-150000.190.4
docker-zsh-completion - update to 24.0.7_ce-150000.190.4
docker-rootless-extras - update to 24.0.7_ce-150000.190.4
microcode_ctl - addressed in versions 20191115-4.20210608.1, 20210216-1.20210608.1
External References
Related Security Bulletins
- Multiple vulnerabilities in Intel RAPL Interface
- RHSA-2020:5181 - Security Advisory
- Red Hat Enterprise Linux 7.4 update for Intel microcode
- Red Hat Enterprise Linux 7.3 update for Intel microcode
- Red Hat Enterprise Linux 8.2 update for Intel microcode
- Red Hat Enterprise Linux Server 8.0 update for Intel microcode
- Red Hat Enterprise Linux 7.2 update for Intel microcode
- Red Hat Enterprise Linux 7.7 update for Intel microcode
- Red Hat Enterprise Linux 8.1 update for microcode_ctl
- Red Hat Enterprise Linux 8.4 update for microcode_ctl
- CentOS 7 update for microcode_ctl
- Red Hat Enterprise Linux 7.7 update for microcode_ctl
- Red Hat Enterprise Linux 7 update for microcode_ctl
- Red Hat Enterprise Linux 8.1 update for microcode_ctl
- Red Hat Enterprise Linux Server 7.6 update for microcode_ctl
- Red Hat Enterprise Linux Server 7.3 update for microcode_ctl
- Red Hat Enterprise Linux Server 7.2 update for microcode_ctl
- Red Hat Enterprise Linux 8.2 update for microcode_ctl
- Ubuntu update for intel-microcode
- Multiple vulnerabilities in Dell EMC Data Computing Appliance (DCA)
- SUSE update for containerd, docker, runc
- Multiple vulnerabilities in containerd
- SUSE update for docker, rootlesskit
- Multiple vulnerabilities in Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software
- Multiple vulnerabilities in IBM Concert
- Red Hat Enterprise Linux 7 update for microcode_ctl
- Anolis OS update for microcode_ctl (Anolis OS 8.4)
- Anolis OS update for microcode_ctl (Anolis OS 8.2)
- Ubuntu update for intel-microcode
- Ubuntu update for intel-microcode
- Red Hat Enterprise Linux 8 update for microcode_ctl
- Red Hat Enterprise Linux 7 update for microcode_ctl
- Fedora 32 update for microcode_ctl
- Fedora 31 update for microcode_ctl
- Fedora 33 update for microcode_ctl
- Fedora 33 update for microcode_ctl
- Fedora 32 update for microcode_ctl
- Fedora 31 update for microcode_ctl