hw: Intel GPU Denial Of Service while accessing MMIO in lower power state
Published Nov 14, 2019
5.5
MEDIUMCVSS 3.1
EPSS 0.65%
Description
Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families may allow an authenticated user to potentially enable denial of service via local access.
Affected products
- Vendor n/a Product 2019.2 IPU – Intel(R) Processor Graphics Update Defaultn/a
- Version See provided referenceStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| n/a | 2019.2 IPU – Intel(R) Processor Graphics Update | n/a |
|
Configuration 1
- 14.04
Configuration 2
- < 26.20.100.6859
Running on/with
- n/a
Configuration 3
- < 26.20.100.6859
Running on/with
- n/a
Configuration 4
- < 26.20.100.6859
Running on/with
- n/a
Configuration 5
- < 26.20.100.6859
Running on/with
- n/a
Configuration 6
- < 26.20.100.6859
Running on/with
- n/a
Configuration 7
- < 26.20.100.6859
Running on/with
- n/a
Configuration 8
- < 26.20.100.6859
Running on/with
- n/a
Configuration 9
- < 26.20.100.6859
Running on/with
- n/a
Configuration 10
- < 26.20.100.6859
Running on/with
- n/a
Configuration 11
- < 26.20.100.6859
Running on/with
- n/a
Configuration 12
- < 26.20.100.6859
Running on/with
- n/a
Configuration 13
- < 26.20.100.6859
Running on/with
- n/a
Configuration 14
- < 26.20.100.6859
Running on/with
- n/a
Configuration 15
- < 26.20.100.6859
Running on/with
- n/a
Configuration 16
- < 26.20.100.6859
Running on/with
- n/a
Configuration 17
- < 26.20.100.6859
Running on/with
- n/a
Configuration 18
- < 26.20.100.6859
Running on/with
- n/a
Configuration 19
- < 26.20.100.6859
Running on/with
- n/a
Configuration 20
- < 26.20.100.6859
Running on/with
- n/a
Configuration 21
- < 26.20.100.6859
Running on/with
- n/a
Configuration 22
- < 26.20.100.6859
Running on/with
- n/a
Configuration 23
- < 26.20.100.6859
Running on/with
- n/a
Configuration 24
- < 26.20.100.6859
Running on/with
- n/a
Configuration 25
- < 26.20.100.6859
Running on/with
- n/a
Configuration 26
- < 26.20.100.6859
Running on/with
- n/a
Configuration 27
- < 26.20.100.6859
Running on/with
- n/a
Configuration 28
- < 26.20.100.6859
Running on/with
- n/a
Configuration 29
- < 26.20.100.6859
Running on/with
- n/a
Configuration 30
- < 26.20.100.6859
Running on/with
- n/a
Configuration 31
- < 26.20.100.6859
Running on/with
- n/a
Configuration 32
- < 26.20.100.6859
Running on/with
- n/a
Configuration 33
- < 26.20.100.6859
Running on/with
- n/a
Configuration 34
- < 26.20.100.6859
Running on/with
- n/a
Configuration 35
- < 26.20.100.6859
Running on/with
- n/a
Configuration 36
- < 26.20.100.6859
Running on/with
- n/a
Configuration 37
- < 26.20.100.6859
Running on/with
- n/a
Configuration 38
- < 26.20.100.6859
Running on/with
- n/a
Configuration 39
- < 26.20.100.6859
Running on/with
- n/a
Configuration 40
- < 26.20.100.6859
Running on/with
- n/a
Configuration 41
- < 26.20.100.6859
Running on/with
- n/a
Configuration 42
- < 26.20.100.6859
Running on/with
- n/a
Configuration 43
- < 26.20.100.6859
Running on/with
- n/a
Configuration 44
- < 26.20.100.6859
Running on/with
- n/a
Configuration 45
- < 26.20.100.6859
Running on/with
- n/a
Configuration 46
- < 26.20.100.6859
- n/a
Running on/with
- n/a
Configuration 47
- < 26.20.100.6859
Running on/with
- n/a
Configuration 48
- < 26.20.100.6859
Running on/with
- n/a
Configuration 49
- < 26.20.100.6859
Running on/with
- n/a
Configuration 50
- < 26.20.100.6859
Running on/with
- n/a
Configuration 51
- < 26.20.100.6859
Running on/with
- n/a
Configuration 52
- < 26.20.100.6859
Running on/with
- n/a
Configuration 53
- < 26.20.100.6859
Running on/with
- n/a
Configuration 54
- < 26.20.100.6859
Running on/with
- n/a
Configuration 55
- < 26.20.100.6859
Running on/with
- n/a
Configuration 56
- < 26.20.100.6859
Running on/with
- n/a
Configuration 57
- < 26.20.100.6859
Running on/with
- n/a
Configuration 58
- < 26.20.100.6859
Running on/with
- n/a
Configuration 59
- < 26.20.100.6859
Running on/with
- n/a
Configuration 60
- < 26.20.100.6859
Running on/with
- n/a
Configuration 61
- < 26.20.100.6859
Running on/with
- n/a
Configuration 62
- < 26.20.100.6859
Running on/with
- n/a
Configuration 63
- < 26.20.100.6859
Running on/with
- n/a
Configuration 64
- < 26.20.100.6859
Running on/with
- n/a
Configuration 65
- < 26.20.100.6859
Running on/with
- n/a
Configuration 66
- < 26.20.100.6859
Running on/with
- n/a
Configuration 67
- < 26.20.100.6859
Running on/with
- n/a
Configuration 68
- < 26.20.100.6859
Running on/with
- n/a
Configuration 69
- < 26.20.100.6859
Running on/with
- n/a
Configuration 70
- < 26.20.100.6859
Running on/with
- n/a
Configuration 71
- < 26.20.100.6859
Running on/with
- n/a
Configuration 72
- < 26.20.100.6859
Running on/with
- n/a
Configuration 73
- < 26.20.100.6859
Running on/with
- n/a
Configuration 74
- < 26.20.100.6859
Running on/with
- n/a
Configuration 75
- < 26.20.100.6859
Running on/with
- n/a
Configuration 76
- < 26.20.100.6859
Running on/with
- n/a
Configuration 77
- < 26.20.100.6859
Running on/with
- n/a
Configuration 78
- < 26.20.100.6859
Running on/with
- n/a
Configuration 79
- < 26.20.100.6859
Running on/with
- n/a
Configuration 80
- < 26.20.100.6859
Running on/with
- n/a
Configuration 81
- < 26.20.100.6859
Running on/with
- n/a
Configuration 82
- < 26.20.100.6859
Running on/with
- n/a
Configuration 83
- < 26.20.100.6859
Running on/with
- n/a
Configuration 84
- < 26.20.100.6859
Running on/with
- n/a
Configuration 85
- < 26.20.100.6859
Running on/with
- n/a
Configuration 86
- < 26.20.100.6859
Running on/with
- n/a
Configuration 87
- < 26.20.100.6859
Running on/with
- n/a
Configuration 88
- < 26.20.100.6859
Running on/with
- n/a
Configuration 89
- < 26.20.100.6859
Running on/with
- n/a
Configuration 90
- < 26.20.100.6859
Running on/with
- n/a
Configuration 91
- < 26.20.100.6859
Running on/with
- n/a
Configuration 92
- < 26.20.100.6859
Running on/with
- n/a
Configuration 93
- < 26.20.100.6859
Running on/with
- n/a
Configuration 94
- < 26.20.100.6859
Running on/with
- n/a
Configuration 95
- < 26.20.100.6859
Running on/with
- n/a
Configuration 96
- < 26.20.100.6859
Running on/with
- n/a
Configuration 97
- < 26.20.100.6859
Running on/with
- n/a
Configuration 98
- < 26.20.100.6859
Running on/with
- n/a
Configuration 99
- < 26.20.100.6859
Running on/with
- n/a
Configuration 100
- < 26.20.100.6859
Running on/with
- n/a
Configuration 101
- < 26.20.100.6859
Running on/with
- n/a
Configuration 102
- < 26.20.100.6859
Running on/with
- n/a
Configuration 103
- < 26.20.100.6859
Running on/with
- n/a
Configuration 104
- < 26.20.100.6859
Running on/with
- n/a
Configuration 105
- < 26.20.100.6859
Running on/with
- n/a
Configuration 106
- < 26.20.100.6859
Running on/with
- n/a
Configuration 107
- < 26.20.100.6859
Running on/with
- n/a
Configuration 108
- < 26.20.100.6859
Running on/with
- n/a
Configuration 109
- < 26.20.100.6859
Running on/with
- n/a
Configuration 110
- < 26.20.100.6859
Running on/with
- n/a
Configuration 111
- < 26.20.100.6859
Running on/with
- n/a
Configuration 112
- < 26.20.100.6859
Running on/with
- n/a
Configuration 113
- < 26.20.100.6859
Running on/with
- n/a
Configuration 114
- < 26.20.100.6859
Running on/with
- n/a
Configuration 115
- < 26.20.100.6859
Running on/with
- n/a
Configuration 116
- < 26.20.100.6859
Running on/with
- n/a
Configuration 117
- < 26.20.100.6859
Running on/with
- n/a
Configuration 118
- < 26.20.100.6859
Running on/with
- n/a
Configuration 119
- < 26.20.100.6859
Running on/with
- n/a
Configuration 120
- < 26.20.100.6859
Running on/with
- n/a
Configuration 121
- < 26.20.100.6859
Running on/with
- n/a
Configuration 122
- < 26.20.100.6859
Running on/with
- n/a
Configuration 123
- < 26.20.100.6859
Running on/with
- n/a
Configuration 124
- < 26.20.100.6859
Running on/with
- n/a
Configuration 125
- < 26.20.100.6859
Running on/with
- n/a
Configuration 126
- < 26.20.100.6859
Running on/with
- n/a
Configuration 127
- < 26.20.100.6859
Running on/with
- n/a
Configuration 128
- < 26.20.100.6859
Running on/with
- n/a
Configuration 129
- < 26.20.100.6859
Running on/with
- n/a
Configuration 130
- < 26.20.100.6859
Running on/with
- n/a
Configuration 131
- < 26.20.100.6859
Running on/with
- n/a
Configuration 132
- < 26.20.100.6859
Running on/with
- n/a
Configuration 133
- < 26.20.100.6859
Running on/with
- n/a
Configuration 134
- < 26.20.100.6859
Running on/with
- n/a
Configuration 135
- < 26.20.100.6859
Running on/with
- n/a
Configuration 136
- < 26.20.100.6859
Running on/with
- n/a
Configuration 137
- < 26.20.100.6859
Running on/with
- n/a
Configuration 138
- < 26.20.100.6859
Running on/with
- n/a
Configuration 139
- < 26.20.100.6859
Running on/with
- n/a
Configuration 140
- < 26.20.100.6859
Running on/with
- n/a
Configuration 141
- < 26.20.100.6859
Running on/with
- n/a
Configuration 142
- < 26.20.100.6859
Running on/with
- n/a
Configuration 143
- < 26.20.100.6859
Running on/with
- n/a
Configuration 144
- < 26.20.100.6859
Running on/with
- n/a
Configuration 145
- < 26.20.100.6859
Running on/with
- n/a
Configuration 146
- < 26.20.100.6859
Running on/with
- n/a
Configuration 147
- < 26.20.100.6859
Running on/with
- n/a
Configuration 148
- < 26.20.100.6859
Running on/with
- n/a
Configuration 149
- < 26.20.100.6859
Running on/with
- n/a
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-754.24.2.el6
Fixed · RHSA-2019:3836
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1062.4.2.el7
Fixed · RHSA-2019:3834
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1062.4.2.rt56.1028.el7
Fixed · RHSA-2019:3835
Red Hat Enterprise Linux 7.2 Advanced Update Support
kernel-0:3.10.0-327.82.2.el7
Fixed · RHSA-2019:3841
Red Hat Enterprise Linux 7.2 Telco Extended Update Support
kernel-0:3.10.0-327.82.2.el7
Fixed · RHSA-2019:3841
Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions
kernel-0:3.10.0-327.82.2.el7
Fixed · RHSA-2019:3841
Red Hat Enterprise Linux 7.3 Advanced Update Support
kernel-0:3.10.0-514.70.2.el7
Fixed · RHSA-2019:3840
Red Hat Enterprise Linux 7.3 Telco Extended Update Support
kernel-0:3.10.0-514.70.2.el7
Fixed · RHSA-2019:3840
Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions
kernel-0:3.10.0-514.70.2.el7
Fixed · RHSA-2019:3840
Red Hat Enterprise Linux 7.4 Advanced Update Support
kernel-0:3.10.0-693.60.2.el7
Fixed · RHSA-2019:3839
Red Hat Enterprise Linux 7.4 Telco Extended Update Support
kernel-0:3.10.0-693.60.2.el7
Fixed · RHSA-2019:3839
Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions
kernel-0:3.10.0-693.60.2.el7
Fixed · RHSA-2019:3839
Red Hat Enterprise Linux 7.5 Extended Update Support
kernel-0:3.10.0-862.43.2.el7
Fixed · RHSA-2019:3838
Red Hat Enterprise Linux 7.6 Extended Update Support
kernel-0:3.10.0-957.38.2.el7
Fixed · RHSA-2019:3837
Red Hat Enterprise Linux 8
kernel-0:4.18.0-147.0.2.el8_1
Fixed · RHSA-2019:3832
Red Hat Enterprise Linux 8
kernel-rt-0:4.18.0-147.0.2.rt24.94.el8_1
Fixed · RHSA-2019:3833
Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions
kernel-0:4.18.0-80.15.1.el8_0
Fixed · RHSA-2020:0204
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-693.60.2.rt56.655.el6rt
Fixed · RHSA-2019:3844
Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS
kernel-0:3.10.0-957.38.2.el7
Fixed · RHSA-2019:3837
Red Hat Enterprise Linux 5
kernel
Will not fix
Red Hat Enterprise Linux 7
kernel-alt
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-754.24.2.el6 | Fixed | RHSA-2019:3836 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1062.4.2.el7 | Fixed | RHSA-2019:3834 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1062.4.2.rt56.1028.el7 | Fixed | RHSA-2019:3835 |
| Red Hat Enterprise Linux 7.2 Advanced Update Support | kernel-0:3.10.0-327.82.2.el7 | Fixed | RHSA-2019:3841 |
| Red Hat Enterprise Linux 7.2 Telco Extended Update Support | kernel-0:3.10.0-327.82.2.el7 | Fixed | RHSA-2019:3841 |
| Red Hat Enterprise Linux 7.2 Update Services for SAP Solutions | kernel-0:3.10.0-327.82.2.el7 | Fixed | RHSA-2019:3841 |
| Red Hat Enterprise Linux 7.3 Advanced Update Support | kernel-0:3.10.0-514.70.2.el7 | Fixed | RHSA-2019:3840 |
| Red Hat Enterprise Linux 7.3 Telco Extended Update Support | kernel-0:3.10.0-514.70.2.el7 | Fixed | RHSA-2019:3840 |
| Red Hat Enterprise Linux 7.3 Update Services for SAP Solutions | kernel-0:3.10.0-514.70.2.el7 | Fixed | RHSA-2019:3840 |
| Red Hat Enterprise Linux 7.4 Advanced Update Support | kernel-0:3.10.0-693.60.2.el7 | Fixed | RHSA-2019:3839 |
| Red Hat Enterprise Linux 7.4 Telco Extended Update Support | kernel-0:3.10.0-693.60.2.el7 | Fixed | RHSA-2019:3839 |
| Red Hat Enterprise Linux 7.4 Update Services for SAP Solutions | kernel-0:3.10.0-693.60.2.el7 | Fixed | RHSA-2019:3839 |
| Red Hat Enterprise Linux 7.5 Extended Update Support | kernel-0:3.10.0-862.43.2.el7 | Fixed | RHSA-2019:3838 |
| Red Hat Enterprise Linux 7.6 Extended Update Support | kernel-0:3.10.0-957.38.2.el7 | Fixed | RHSA-2019:3837 |
| Red Hat Enterprise Linux 8 | kernel-0:4.18.0-147.0.2.el8_1 | Fixed | RHSA-2019:3832 |
| Red Hat Enterprise Linux 8 | kernel-rt-0:4.18.0-147.0.2.rt24.94.el8_1 | Fixed | RHSA-2019:3833 |
| Red Hat Enterprise Linux 8.0 Update Services for SAP Solutions | kernel-0:4.18.0-80.15.1.el8_0 | Fixed | RHSA-2020:0204 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-693.60.2.rt56.655.el6rt | Fixed | RHSA-2019:3844 |
| Red Hat Virtualization 4.2 for Red Hat Enterprise Linux 7.6 EUS | kernel-0:3.10.0-957.38.2.el7 | Fixed | RHSA-2019:3837 |
| Red Hat Enterprise Linux 5 | kernel | Will not fix | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
Intel plans to release BIOS firmware to correct this issue. Red Hat's kernel update should mitigate this vulnerability. Some older hardware will not have BIOS firmware update and will rely on operating system level protection to prevent access while the device is in low-power states. For more information see https://access.redhat.com/solutions/i915-graphics
Red Hat mitigation
Preventing loading of the i915 kernel module will prevent attackers from using this exploit against the system however the power management functionality of the card will be disabled and the system may draw additional power. See this KCS article (https://access.redhat.com/solutions/41278) for instructions on how to disable a kernel module. Graphical displays may also be at low resolution or not work correctly. This mitigation may not be suitable if running graphical tools locally is required.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H
AV:L/AC:L/Au:N/C:N/I:N/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v1
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (16 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.65% (0.00646) | 49.06th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.65% (0.00646) | 45.92th | v5 (v2026.06.15) |
| Mar 30, 2025 | 0.08% (0.00082) | 21.14th | v4 (v2025.03.14) |
| Mar 29, 2025 | 1.49% (0.01490) | 69.25th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.11% (0.00110) | 26.98th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.07% (0.00074) | 34.11th | v3 (v2023.03.01) |
| Jun 10, 2024 | 0.04% (0.00045) | 14.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00045) | 12.06th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.03% (0.01034) | 41.69th | v2 (v2022.01.01) |
| Sep 10, 2022 | 1.03% (0.01034) | 39.91th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.03% (0.01034) | 37.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.09% (0.03090) | 64.78th | v2 (v2022.01.01) |
| Feb 3, 2022 | 8.63% (0.08626) | 85.56th | v1 |
| Jan 6, 2022 | 8.63% (0.08626) | 85.39th | v1 |
| Sep 1, 2021 | 2.06% (0.02061) | 76.87th | v1 |
| Apr 14, 2021 | 2.06% (0.02061) | 0.00th | v1 |
References (12)
- http://packetstormsecurity.com/files/155375/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html x_refsource_MISCThird Party Advisory
- https://access.redhat.com/errata/RHSA-2020:0204 vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2019-0154 Vendor Advisory
- https://access.redhat.com/solutions/i915-graphics
- https://bugzilla.redhat.com/show_bug.cgi?id=1724393 Issue Tracking
- https://nvd.nist.gov/vuln/detail/CVE-2019-0154
- https://seclists.org/bugtraq/2019/Nov/26 mailing-listx_refsource_BUGTRAQIssue TrackingMailing ListThird Party Advisory
- https://security.netapp.com/advisory/ntap-20200320-0004/ x_refsource_CONFIRM
- https://support.f5.com/csp/article/K73659122?utm_source=f5support&%3Butm_medium=RSS x_refsource_CONFIRM
- https://usn.ubuntu.com/4186-2/ vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2019-0154
- https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00260.html x_refsource_MISCVendor Advisory
Change history (0)
No recorded changes yet.