PT-2019-4060 · Intel+5 · Intel Xeon Processors+9

Published

2019-11-05

·

Updated

2020-08-24

·

CVE-2019-0154

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Intel(R) Core(TM) Processor Families versions 6th through 9th Intel(R) Pentium(R) Processor J, N, Silver and Gold Series Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series Intel(R) Atom(R) Processor A and E3900 Series Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
Description The issue is related to insufficient access control in a subsystem for Intel processor graphics, which may allow an authenticated user to potentially enable denial of service via local access. The vulnerability exists due to inadequate input validation, and its exploitation can lead to a denial of service.
Recommendations For Intel(R) Core(TM) Processor Families versions 6th through 9th: Update to a version with improved access control. For Intel(R) Pentium(R) Processor J, N, Silver and Gold Series: Apply configuration changes to restrict local access. For Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series: Disable vulnerable subsystems until a patch is available. For Intel(R) Atom(R) Processor A and E3900 Series: Restrict input validation to prevent exploitation. For Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families: Implement additional security measures to prevent denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04621
CESA-2019_3832
CESA-2019_3833
CESA-2019_3834
CESA-2019_3836
CVE-2019-0154
DLA-1989-1
DLA-1990-1
DSA-4564-1
OPENSUSE-SU-2019:2503-1
OPENSUSE-SU-2019:2507-1
OPENSUSE-SU-2019_2503-1
OPENSUSE-SU-2019_2507-1
RHSA-2019:3832
RHSA-2019:3833
RHSA-2019:3834
RHSA-2019:3835
RHSA-2019:3836
RHSA-2019:3837
RHSA-2019:3838
RHSA-2019:3839
RHSA-2019:3840
RHSA-2019:3841
RHSA-2019:3844
RHSA-2019_3832
RHSA-2019_3833
RHSA-2019_3834
RHSA-2019_3835
RHSA-2019_3836
RHSA-2020:0204
SUSE-SU-2019:2946-1
SUSE-SU-2019:2948-1
SUSE-SU-2019:2949-1
SUSE-SU-2019:2984-1
SUSE-SU-2019:3200-1
SUSE-SU-2019:3289-1
SUSE-SU-2019:3294-1
SUSE-SU-2019:3295-1
SUSE-SU-2019:3316-1
SUSE-SU-2019:3317-1
SUSE-SU-2019:3372-1
SUSE-SU-2020:0093-1
USN-4183-1
USN-4184-1
USN-4185-1
USN-4186-1
USN-4186-2

Affected Products

Astra Linux
Centos
Intel Atom Processors
Intel Celeron Processor
Intel Core Processor Families
Intel Pentium Processor
Intel Xeon Processors
Red Hat
Suse
Ubuntu