Vulnerabilities in the Intel i915 video driver

In Intel i915 graphics driver identified two vulnerabilities. First vulnerability (CVE-2019-0155) affects systems with Intel Gen9 GPU (Skylake) and allows you to change entries in the memory page table from user space through manipulations with MMIO (Memory Mapped Input Output). The issue allows an attacker to gain access to information stored in kernel memory and potentially escalate their privileges on the system.

The second problem (CVE-2019-0154) appears on systems with Intel Gen8 and Gen9 GPUs (Broadwell and Skylake), and can be used to initiate a denial of service (system hang) by accessing certain GPU registers via MMIO, resulting in the GPU being placed in an incorrect state.

Problems eliminated in Linux kernel updates 5.4-rc7, 5.3.11, 4.19.84, 4.14.154, 4.9.201, 4.4.201. Package updates have already been released for most distributions: Debian, Ubuntu, RHEL, Arch Linux, openSUSE / SUSE, Fedora.

Source: opennet.ru

Add a comment