PT-2019-4002 · Intel+4 · Intel Xeon Processors+10

Published

2019-11-05

·

Updated

2022-04-22

·

CVE-2019-0155

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Intel Graphics Driver versions prior to 26.20.100.6813 (DCH) or 26.20.100.6812 and prior to 21.20.x.5077 (aka15.45.5077) i915 Linux Driver for Intel Processor Graphics versions prior to 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201 Intel Core Processor Families 6th, 7th, 8th and 9th Generation Intel Pentium Processor J, N, Silver and Gold Series Intel Celeron Processor J, N, G3900 and G4900 Series Intel Atom Processor A and E3900 Series Intel Xeon Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor Families
Description The issue is related to insufficient access control in a subsystem for Intel processor graphics, which may allow an authenticated user to potentially enable escalation of privilege via local access. The problem is associated with the lack of security checks in the bit array copy command buffer (BCS) of the Intel i915 graphics driver microcode. Exploitation of the issue may allow an attacker to modify entries in the page table through MMIO (Memory Mapped Input Output) manipulations and potentially elevate their privileges.
Recommendations For Intel Graphics Driver versions prior to 26.20.100.6813 (DCH) or 26.20.100.6812 and prior to 21.20.x.5077 (aka15.45.5077), update to version 26.20.100.6813 (DCH) or 26.20.100.6812 and 21.20.x.5077 (aka15.45.5077) or later. For i915 Linux Driver for Intel Processor Graphics versions prior to 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201, update to version 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201 or later. As a temporary workaround, consider restricting access to the MMIO (Memory Mapped Input Output) to minimize the risk of exploitation.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04533
CESA-2019_3870
CESA-2019_3871
CESA-2019_3872
CESA-2019_3878
CVE-2019-0155
DLA-1990-1
DSA-4564-1
MGASA-2019-0332
MGASA-2019-0333
OPENSUSE-SU-2019:2503-1
OPENSUSE-SU-2019:2507-1
OPENSUSE-SU-2019_2503-1
OPENSUSE-SU-2019_2507-1
RHSA-2019:3841
RHSA-2019:3870
RHSA-2019:3871
RHSA-2019:3872
RHSA-2019:3873
RHSA-2019:3877
RHSA-2019:3878
RHSA-2019:3883
RHSA-2019:3887
RHSA-2019:3889
RHSA-2019:3908
RHSA-2019_3870
RHSA-2019_3871
RHSA-2019_3872
RHSA-2019_3878
RHSA-2019_3887
RHSA-2020:0204
SUSE-SU-2019:2946-1
SUSE-SU-2019:2948-1
SUSE-SU-2019:2949-1
SUSE-SU-2019:2984-1
SUSE-SU-2019:3200-1
SUSE-SU-2019:3289-1
SUSE-SU-2019:3294-1
SUSE-SU-2019:3295-1
SUSE-SU-2020:0093-1
SUSE-SU-2020:2491-1
SUSE-SU-2020:2497-1
SUSE-SU-2020:2505-1
SUSE-SU-2020:2526-1
USN-4183-1
USN-4183-2
USN-4184-1
USN-4184-2
USN-4185-1
USN-4185-3
USN-4186-1
USN-4186-2
USN-4186-3

Affected Products

Centos
Intel Atom Processors
Intel Celeron Processor
Intel Core Processor
Intel Graphics Driver
Intel Pentium Processor
Intel Xeon Processors
Red Hat
Suse
Ubuntu
I915 Linux Driver