CVE-2020-8696: Medium severity microcode vulnerability
A flaw was found in the implementation of Intel Advanced Vector Extensions (AVX) where a local authenticated attacker with the ability to execute AVX instructions is able to gather AVX register state from previous AVX executions.
This could allow information disclosure of AVX register state.
Other sources
A flaw was found in the Intel Advanced Vector Extensions (AVX) implementation, where a local authenticated attacker with the ability to execute AVX instructions can gather the AVX register state from previous AVX executions. This vulnerability allows information disclosure of the AVX register state.
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
- RHSA-2020:5084
- RHSA-2020:5189
- RHSA-2020:5184
- RHBA-2021:0623
- RHSA-2020:5083
- RHSA-2021:3028
- RHBA-2021:0627
- RHSA-2020:5188
- RHSA-2021:3323
- RHBA-2021:0622
- RHSA-2020:5183
- RHSA-2021:3322
- RHBA-2021:0628
- RHSA-2020:5182
- RHSA-2021:3255
- RHSA-2021:3317
- RHBA-2021:0626
- RHSA-2020:5181
- RHBA-2021:0625
- RHSA-2020:5190
- RHSA-2021:3029
- RHBA-2021:0621
- RHSA-2020:5085
- RHSA-2021:3027
- RHSA-2020:5186
- RHBA-2021:0624
- RHSA-2020:5369
- RHSA-2021:3176
- RHBA-2021:0629
- RHSA-2020:5185
- RHSA-2021:3364
Frequently Asked Questions
What is the severity of CVE-2020-8696?
CVE-2020-8696 has been rated as a medium severity vulnerability due to its potential for information disclosure.
How do I fix CVE-2020-8696?
To fix CVE-2020-8696, users should update to the latest microcode provided by Intel or apply any available patches from their OS vendor.
Who is affected by CVE-2020-8696?
CVE-2020-8696 affects Intel processors that leverage Advanced Vector Extensions (AVX) where previous states can be accessed by an authenticated local attacker.
What type of vulnerability is CVE-2020-8696?
CVE-2020-8696 is an information disclosure vulnerability caused by improper handling of previously executed AVX instructions.
Can CVE-2020-8696 be exploited remotely?
No, CVE-2020-8696 can only be exploited by a local authenticated attacker with access to execute AVX instructions.