Information disclosure in AMD Energy Driver for Linux - CVE-2020-12912
Published: November 11, 2020
Vulnerability identifier: #VU48373
CSH Severity: Low
CVSS v4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-12912
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to excessive data output by the application in the Running Average Power Limit (RAPL) interface. A local user can gain unauthorized access to sensitive information on the system.
Affected software
AMD Energy Driver for Linux
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
containerd
IBM Concert Software
Azure Stack
rootlesskit
rootlesskit-debuginfo
runc-debuginfo
runc
containerd
linux-image-5.8.0-34-generic-64k (Ubuntu package)
linux-image-5.8.0-34-lowlatency (Ubuntu package)
linux-image-5.8.0-34-generic-lpae (Ubuntu package)
linux-image-5.8.0-34-generic (Ubuntu package)
linux-image-virtual-hwe-20.04 (Ubuntu package)
linux-image-lowlatency-hwe-20.04 (Ubuntu package)
linux-image-generic-lpae-hwe-20.04 (Ubuntu package)
linux-image-generic-hwe-20.04 (Ubuntu package)
linux-image-virtual (Ubuntu package)
linux-image-lowlatency (Ubuntu package)
linux-image-generic-lpae (Ubuntu package)
linux-image-generic-64k (Ubuntu package)
linux-image-generic (Ubuntu package)
linux-image-5.8.0-1011-raspi (Ubuntu package)
linux-image-5.8.0-1011-raspi-nolpae (Ubuntu package)
linux-image-raspi-nolpae (Ubuntu package)
linux-image-raspi (Ubuntu package)
linux-image-5.8.0-1014-oracle (Ubuntu package)
linux-image-oracle (Ubuntu package)
linux-image-5.8.0-1014-kvm (Ubuntu package)
linux-image-kvm (Ubuntu package)
linux-image-gcp (Ubuntu package)
linux-image-gke (Ubuntu package)
linux-image-5.8.0-1015-gcp (Ubuntu package)
linux-image-azure (Ubuntu package)
linux-image-5.8.0-1016-azure (Ubuntu package)
linux-image-5.8.0-1017-aws (Ubuntu package)
linux-image-aws (Ubuntu package)
docker-debuginfo
docker
docker-rootless-extras
docker-bash-completion
docker-zsh-completion
docker-fish-completion
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise High Performance Computing LTSS 15
SUSE Linux Enterprise High Performance Computing ESPOS 15
SUSE Linux Enterprise Real Time 15
SUSE CaaS Platform
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
SUSE Enterprise Storage
Containers Module
SUSE Linux Enterprise Server
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise High Performance Computing 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP1 LTSS
SUSE Linux Enterprise Server 15 SP2 LTSS
SUSE Linux Enterprise High Performance Computing 15 SP2 LTSS
SUSE Linux Enterprise Server 15 SP3 LTSS
openSUSE Leap
Ubuntu
containerd
IBM Concert Software
Azure Stack
rootlesskit
rootlesskit-debuginfo
runc-debuginfo
runc
containerd
linux-image-5.8.0-34-generic-64k (Ubuntu package)
linux-image-5.8.0-34-lowlatency (Ubuntu package)
linux-image-5.8.0-34-generic-lpae (Ubuntu package)
linux-image-5.8.0-34-generic (Ubuntu package)
linux-image-virtual-hwe-20.04 (Ubuntu package)
linux-image-lowlatency-hwe-20.04 (Ubuntu package)
linux-image-generic-lpae-hwe-20.04 (Ubuntu package)
linux-image-generic-hwe-20.04 (Ubuntu package)
linux-image-virtual (Ubuntu package)
linux-image-lowlatency (Ubuntu package)
linux-image-generic-lpae (Ubuntu package)
linux-image-generic-64k (Ubuntu package)
linux-image-generic (Ubuntu package)
linux-image-5.8.0-1011-raspi (Ubuntu package)
linux-image-5.8.0-1011-raspi-nolpae (Ubuntu package)
linux-image-raspi-nolpae (Ubuntu package)
linux-image-raspi (Ubuntu package)
linux-image-5.8.0-1014-oracle (Ubuntu package)
linux-image-oracle (Ubuntu package)
linux-image-5.8.0-1014-kvm (Ubuntu package)
linux-image-kvm (Ubuntu package)
linux-image-gcp (Ubuntu package)
linux-image-gke (Ubuntu package)
linux-image-5.8.0-1015-gcp (Ubuntu package)
linux-image-azure (Ubuntu package)
linux-image-5.8.0-1016-azure (Ubuntu package)
linux-image-5.8.0-1017-aws (Ubuntu package)
linux-image-aws (Ubuntu package)
docker-debuginfo
docker
docker-rootless-extras
docker-bash-completion
docker-zsh-completion
docker-fish-completion
How to mitigate CVE-2020-12912
Install updates from vendor's website.
containerd - addressed in versions 1.6.26, 1.7.11
IBM Concert Software - update to 1.0.1
rootlesskit - update to 1.1.1-150000.1.3.3
rootlesskit-debuginfo - update to 1.1.1-150000.1.3.3
runc-debuginfo - update to 1.1.10-16.40.1
runc - update to 1.1.10-16.40.1
containerd - update to 1.7.8-16.88.1
linux-image-5.8.0-34-generic-64k (Ubuntu package) - update to 5.8.0-34.37
linux-image-5.8.0-34-lowlatency (Ubuntu package) - update to 5.8.0-34.37~20.04.2
linux-image-5.8.0-34-generic-lpae (Ubuntu package) - update to 5.8.0-34.37~20.04.2
linux-image-5.8.0-34-generic (Ubuntu package) - update to 5.8.0-34.37~20.04.2
linux-image-virtual-hwe-20.04 (Ubuntu package) - update to 5.8.0.34.37~20.04.20
linux-image-lowlatency-hwe-20.04 (Ubuntu package) - update to 5.8.0.34.37~20.04.20
linux-image-generic-lpae-hwe-20.04 (Ubuntu package) - update to 5.8.0.34.37~20.04.20
linux-image-generic-hwe-20.04 (Ubuntu package) - update to 5.8.0.34.37~20.04.20
linux-image-virtual (Ubuntu package) - update to 5.8.0.34.39
linux-image-lowlatency (Ubuntu package) - update to 5.8.0.34.39
linux-image-generic-lpae (Ubuntu package) - update to 5.8.0.34.39
linux-image-generic-64k (Ubuntu package) - update to 5.8.0.34.39
linux-image-generic (Ubuntu package) - update to 5.8.0.34.39
linux-image-5.8.0-1011-raspi (Ubuntu package) - update to 5.8.0-1011.14
linux-image-5.8.0-1011-raspi-nolpae (Ubuntu package) - update to 5.8.0-1011.14
linux-image-raspi-nolpae (Ubuntu package) - update to 5.8.0.1011.14
linux-image-raspi (Ubuntu package) - update to 5.8.0.1011.14
linux-image-5.8.0-1014-oracle (Ubuntu package) - update to 5.8.0-1014.14
linux-image-oracle (Ubuntu package) - update to 5.8.0.1014.14
linux-image-5.8.0-1014-kvm (Ubuntu package) - update to 5.8.0-1014.15
linux-image-kvm (Ubuntu package) - update to 5.8.0.1014.16
linux-image-gcp (Ubuntu package) - update to 5.8.0.1015.15
linux-image-gke (Ubuntu package) - update to 5.8.0.1015.15
linux-image-5.8.0-1015-gcp (Ubuntu package) - update to 5.8.0-1015.15
linux-image-azure (Ubuntu package) - update to 5.8.0.1016.16
linux-image-5.8.0-1016-azure (Ubuntu package) - update to 5.8.0-1016.17
linux-image-5.8.0-1017-aws (Ubuntu package) - update to 5.8.0-1017.18
linux-image-aws (Ubuntu package) - update to 5.8.0.1017.19
Azure Stack - update to 10.2402
docker-debuginfo - addressed in versions 24.0.7_ce-98.103.1, 24.0.7_ce-150000.190.4
docker - addressed in versions 24.0.7_ce-98.103.1, 24.0.7_ce-150000.190.4
docker-rootless-extras - update to 24.0.7_ce-150000.190.4
docker-bash-completion - update to 24.0.7_ce-150000.190.4
docker-zsh-completion - update to 24.0.7_ce-150000.190.4
docker-fish-completion - update to 24.0.7_ce-150000.190.4
IBM Concert Software - update to 1.0.1
rootlesskit - update to 1.1.1-150000.1.3.3
rootlesskit-debuginfo - update to 1.1.1-150000.1.3.3
runc-debuginfo - update to 1.1.10-16.40.1
runc - update to 1.1.10-16.40.1
containerd - update to 1.7.8-16.88.1
linux-image-5.8.0-34-generic-64k (Ubuntu package) - update to 5.8.0-34.37
linux-image-5.8.0-34-lowlatency (Ubuntu package) - update to 5.8.0-34.37~20.04.2
linux-image-5.8.0-34-generic-lpae (Ubuntu package) - update to 5.8.0-34.37~20.04.2
linux-image-5.8.0-34-generic (Ubuntu package) - update to 5.8.0-34.37~20.04.2
linux-image-virtual-hwe-20.04 (Ubuntu package) - update to 5.8.0.34.37~20.04.20
linux-image-lowlatency-hwe-20.04 (Ubuntu package) - update to 5.8.0.34.37~20.04.20
linux-image-generic-lpae-hwe-20.04 (Ubuntu package) - update to 5.8.0.34.37~20.04.20
linux-image-generic-hwe-20.04 (Ubuntu package) - update to 5.8.0.34.37~20.04.20
linux-image-virtual (Ubuntu package) - update to 5.8.0.34.39
linux-image-lowlatency (Ubuntu package) - update to 5.8.0.34.39
linux-image-generic-lpae (Ubuntu package) - update to 5.8.0.34.39
linux-image-generic-64k (Ubuntu package) - update to 5.8.0.34.39
linux-image-generic (Ubuntu package) - update to 5.8.0.34.39
linux-image-5.8.0-1011-raspi (Ubuntu package) - update to 5.8.0-1011.14
linux-image-5.8.0-1011-raspi-nolpae (Ubuntu package) - update to 5.8.0-1011.14
linux-image-raspi-nolpae (Ubuntu package) - update to 5.8.0.1011.14
linux-image-raspi (Ubuntu package) - update to 5.8.0.1011.14
linux-image-5.8.0-1014-oracle (Ubuntu package) - update to 5.8.0-1014.14
linux-image-oracle (Ubuntu package) - update to 5.8.0.1014.14
linux-image-5.8.0-1014-kvm (Ubuntu package) - update to 5.8.0-1014.15
linux-image-kvm (Ubuntu package) - update to 5.8.0.1014.16
linux-image-gcp (Ubuntu package) - update to 5.8.0.1015.15
linux-image-gke (Ubuntu package) - update to 5.8.0.1015.15
linux-image-5.8.0-1015-gcp (Ubuntu package) - update to 5.8.0-1015.15
linux-image-azure (Ubuntu package) - update to 5.8.0.1016.16
linux-image-5.8.0-1016-azure (Ubuntu package) - update to 5.8.0-1016.17
linux-image-5.8.0-1017-aws (Ubuntu package) - update to 5.8.0-1017.18
linux-image-aws (Ubuntu package) - update to 5.8.0.1017.19
Azure Stack - update to 10.2402
docker-debuginfo - addressed in versions 24.0.7_ce-98.103.1, 24.0.7_ce-150000.190.4
docker - addressed in versions 24.0.7_ce-98.103.1, 24.0.7_ce-150000.190.4
docker-rootless-extras - update to 24.0.7_ce-150000.190.4
docker-bash-completion - update to 24.0.7_ce-150000.190.4
docker-zsh-completion - update to 24.0.7_ce-150000.190.4
docker-fish-completion - update to 24.0.7_ce-150000.190.4
External References
Related Security Bulletins
- Information disclosure in AMD Energy Driver for Linux
- SUSE update for containerd, docker, runc
- Multiple vulnerabilities in containerd
- SUSE update for docker, rootlesskit
- Multiple vulnerabilities in Dell APEX Cloud Platform for Microsoft Azure and Dell APEX Cloud Platform Foundation Software
- Multiple vulnerabilities in IBM Concert
- Ubuntu update for linux