Observable Response Discrepancy in Intel products - CVE-2020-8695

 

Observable Response Discrepancy in Intel products - CVE-2020-8695

Published: November 11, 2020


Vulnerability identifier: #VU48372
CSH Severity: Low
CVSS v4: 5.6 [CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-8695
CWE-ID: CWE-204
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to observable discrepancy in the Running Average Power Limit (RAPL) Interface. A local administrator can gain access to sensitive information on the target system.

Affected products:

Product Collection

Vertical Segment

CPUID

8th Generation Intel® Core™ Processor Family

Mobile

806E9

10th Generation Intel® Core™ Processor Family

Mobile

806EC

8th Generation Intel® Core™ Processor Family

Mobile

906EA

9th Generation Intel® Core™ Processor Family

Mobile

906EC

8th Generation Intel® Core™ Processor Family

Desktop

906EA

9th Generation Intel® Core™ Processor Family

Desktop

906EC

Intel® Xeon® Processor E Family

Server Workstation AMT Server

906EA

8th Generation Intel® Core™ Processor Family

Mobile

806EA

8th Generation Intel® Core™ Processor Family Intel® Pentium® Gold Processor Series Intel® Celeron® Processor G Series

Desktop

906EB

Intel® Xeon® Processor E Family

Server Workstation AMT Server

906EA

8th Generation Intel® Core™ Processor Family

Desktop

906EA

9th Generation Intel® Core™ Processor Family

Desktop

906ED

9th Generation Intel® Core™ Processor Family

Desktop

906ED

10th Generation Intel® Core™ Processor Family

Mobile

A0660

10th Generation Intel® Core™ Processor Family

Mobile

A0661

10th Generation Intel® Core™ Processor Family

Mobile

806EC

10th Generation Intel® Core™ Processor Family

Desktop

A0653

10th Generation Intel® Core™ Processor Family

Mobile

A0655

10th Generation Intel® Core™ Processor Family

Mobile

A0652

Intel® Pentium® Processor Silver Series Intel® Celeron® Processor J Series Intel® Celeron® Processor N Series

Desktop Mobile Embedded

706A1

Intel® Pentium® Processor Silver Series Intel® Celeron® Processor J Series Intel® Celeron® Processor N Series

Desktop Mobile Embedded

706A8

10th Generation Intel® Core™ Processor Family

Mobile

706E5

8th Generation Intel® Core™ Processor Family

Mobile

906E9

7th Generation Intel® Core™ Processor Family

Mobile Embedded

906E9

8th Generation Intel® Core™  Processor Family

Mobile

806EA

7th Generation Intel® Core™ Processor Family

Desktop Embedded

906E9

7th Generation Intel® Core™ Processor Family

Mobile

806E9

7th Generation Intel® Core™

Processor Family

Mobile

806E9

Intel® Core™ X-series Processors

Desktop

906E9

Intel® Xeon® Processor E3 v6 Family

Server Workstation AMT Server

906E9

7th Generation Intel® Core™ Processor Family

Mobile

806E9

6th Generation Intel® Core™ Processor Family

Mobile

506E3

6th Generation Intel® Core™ Processor Family

Desktop Embedded

506E3

6th Generation Intel® Core™ Processors

Mobile

406E3

6th Generation Intel® Core™ Processor Family

Mobile

406E3

Intel® Xeon® Processor E3 v5 Family

Server Workstation AMT Server

506E3

6th Generation Intel® Core™ Processor Family

Mobile

406E3

8th Generation Intel® Core™ Processors

Mobile

806EB

8th Generation Intel® Core™ Processors

Mobile

806EC


Affected software

8th Generation Intel Core Processors
10th Generation Intel Core Processors
Intel Xeon Processor E Family
Intel Pentium Processor Silver Series
Intel Celeron Processor J Series
Intel Celeron Processor N Series
7th Generation Intel Core Processors
Intel Core X-series Processors
Intel Xeon Processor E3 v6 Family
6th Generation Intel Core Processors
Intel Xeon Processor E3 v5 Family
9th Generation Intel Core Processors
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
CentOS
SUSE Enterprise Storage
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for x86_64
Anolis OS
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
Ubuntu
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Fedora
containerd
Data Computing Appliance (DCA)
microcode_ctl (Red Hat package)
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
rootlesskit
rootlesskit-debuginfo
runc
runc-debuginfo
containerd
microcode_ctl
intel-microcode (Ubuntu package)
docker
docker-debuginfo
docker-bash-completion
docker-fish-completion
docker-zsh-completion
docker-rootless-extras
IBM Concert Software
Azure Stack

How to mitigate CVE-2020-8695

Install updates from vendor's website.

containerd - addressed in versions 1.6.26, 1.7.11
microcode_ctl (Red Hat package) - addressed in versions 2.1-12.34.el7_2, 2.1-12.39.el7_2, 2.1-16.37.el7_3, 2.1-16.42.el7_3, 2.1-22.36.el7_4, 2.1-22.41.el7_4, 2.1-47.18.el7_6, 2.1-47.23.el7_6, 2.1-53.13.el7_7, 2.1-53.18.el7_7, 2.1-73.2.el7_9, 2.1-73.11.el7_9, 20180807a-2.20201112.1.el8_0, 20190618-1.20201112.1.el8_1, 20190618-1.20210608.1.el8_1, 20191115-4.20201112.1.el8_2, 20191115-4.20210608.1.el8_2, 20200609-2.20201027.1.el8_3, 20210216-1.20210608.1.el8_4
Data Computing Appliance (DCA) - addressed in versions Firmware tool 3H00, 4.2.1.0
IBM Concert Software - update to 1.0.1
rootlesskit - update to 1.1.1-150000.1.3.3
rootlesskit-debuginfo - update to 1.1.1-150000.1.3.3
runc - update to 1.1.10-16.40.1
runc-debuginfo - update to 1.1.10-16.40.1
containerd - update to 1.7.8-16.88.1
microcode_ctl - addressed in versions 2.1-39.2.fc31, 2.1-39.2.fc32, 2.1-39.3.fc31, 2.1-39.3.fc32, 2.1-42.fc33, 2.1-43.fc33
intel-microcode (Ubuntu package) - addressed in versions 3.20201110.0ubuntu0.16.04.1, 3.20201110.0ubuntu0.16.04.2, 3.20201110.0ubuntu0.18.04.1, 3.20201110.0ubuntu0.18.04.2, 3.20201110.0ubuntu0.20.04.1, 3.20201110.0ubuntu0.20.04.2, 3.20201110.0ubuntu0.20.10.1, 3.20201110.0ubuntu0.20.10.2, 3.20210216.0ubuntu0.18.04.1, 3.20210216.0ubuntu0.20.04.1, 3.20210216.0ubuntu0.20.10.1, 3.20210216.0ubuntu0.21.04.1
Azure Stack - update to 10.2402
docker - addressed in versions 24.0.7_ce-98.103.1, 24.0.7_ce-150000.190.4
docker-debuginfo - addressed in versions 24.0.7_ce-98.103.1, 24.0.7_ce-150000.190.4
docker-bash-completion - update to 24.0.7_ce-150000.190.4
docker-fish-completion - update to 24.0.7_ce-150000.190.4
docker-zsh-completion - update to 24.0.7_ce-150000.190.4
docker-rootless-extras - update to 24.0.7_ce-150000.190.4
microcode_ctl - addressed in versions 20191115-4.20210608.1, 20210216-1.20210608.1

External References

Related Security Bulletins