Rapid7 Vulnerability & Exploit Database

FreeBSD: VID-D2C2C815-3793-11EA-8BE3-54E1AD3D6335 (CVE-2019-14615): drm graphics drivers -- potential information disclusure via local access

Back to Search

FreeBSD: VID-D2C2C815-3793-11EA-8BE3-54E1AD3D6335 (CVE-2019-14615): drm graphics drivers -- potential information disclusure via local access

Severity
2
CVSS
(AV:L/AC:M/Au:N/C:P/I:N/A:N)
Published
01/14/2020
Created
01/17/2020
Added
01/16/2020
Modified
02/20/2020

Description

Details for this vulnerability have not been published by NIST at this point. Descriptions from software vendor advisories for this issue are provided below.

From VID-D2C2C815-3793-11EA-8BE3-54E1AD3D6335:

Intel reports:

.A potential security vulnerability in Intel(R) Processor Graphics

may allow information disclosure. Intel is releasing software

updates to mitigate this potential vulnerability.

Description: Insufficient control flow in certain data

structures for some Intel(R) Processors with Intel(R) Processor

Graphics may allow an unauthenticated user to potentially enable

information disclosure via local access.

This patch provides mitigation for Gen9 hardware only. Patches

for Gen7 and Gen7.5 will be provided later. Note that Gen8 is not

impacted due to a previously implemented workaround. The mitigation

involves using an existing hardware feature to forcibly clear down

all EU state at each context switch.

Solution(s)

  • freebsd-upgrade-package-drm-current-kmod
  • freebsd-upgrade-package-drm-devel-kmod
  • freebsd-upgrade-package-drm-fbsd11-2-kmod
  • freebsd-upgrade-package-drm-fbsd12-0-kmod

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;