The fix for the Linux kernel in Ubuntu 18.04 LTS for CVE-2019-14615 ("The Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors.") was discovered to be incomplete, meaning that in versions of the kernel before 4.15.0-91.92, an attacker could use this vulnerability to expose sensitive information.
Conclusion & alert: CVE-2020-8832 is rated Moderate Risk (40.5/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.31%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-10-12 | 0.65% | 0.31% | -0.34% |
| 2 | 2025-03-30 | 6.43% | 0.65% | -5.78% |
| 3 | 2025-03-29 | — | 6.43% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 5.5 | 3.1 | MEDIUM |
|
1.8 | 3.6 | [email protected] |
| 2.1 | 2.0 | LOW |
|
3.9 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2020-8832 not yet assigned priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-8832 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2020-8832 |
suse
|
medium | CVE-2020-8832 severity moderate: SUSE including 7 source package names (kernel-default, kernel-default-base, …), 60 product×package rows across 16 product lines (SUSE Linux Enterprise High Performance Computing 12 SP4, SUSE Linux Enterprise High Performance Computing 12 SP5, … (16 product lines)): Known Not Affected 60. | https://www.suse.com/security/cve/CVE-2020-8832/ |
ubuntu
|
medium | CVE-2020-8832 medium priority: Ubuntu including 27 source packages (linux, linux-aws, …), 135 status rows across 5 suites (bionic, eoan, trusty, upstream, xenial): DNE 59, not-affected 42, released 13, needs-triage 12, ignored 9. | https://ubuntu.com/security/CVE-2020-8832 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| canonical | ubuntu_linux | 18.04 | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
| netapp | cloud_backup | — | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* |
| netapp | solidfire_\&_hci_management_node | — | cpe:2.3:a:netapp:solidfire_\&_hci_management_node:-:*:*:*:*:*:*:* |
| netapp | steelstore_cloud_integrated_storage | — | cpe:2.3:a:netapp:steelstore_cloud_integrated_storage:-:*:*:*:*:*:*:* |
| netapp | aff_8300_firmware | — | cpe:2.3:o:netapp:aff_8300_firmware:-:*:*:*:*:*:*:* |
| netapp | aff_8700_firmware | — | cpe:2.3:o:netapp:aff_8700_firmware:-:*:*:*:*:*:*:* |
| netapp | aff_a220_firmware | — | cpe:2.3:o:netapp:aff_a220_firmware:-:*:*:*:*:*:*:* |
| netapp | aff_a320_firmware | — | cpe:2.3:o:netapp:aff_a320_firmware:-:*:*:*:*:*:*:* |
| netapp | aff_a400_firmware | — | cpe:2.3:o:netapp:aff_a400_firmware:-:*:*:*:*:*:*:* |
| netapp | aff_a700s_firmware | — | cpe:2.3:o:netapp:aff_a700s_firmware:-:*:*:*:*:*:*:* |
| netapp | aff_c190_firmware | — | cpe:2.3:o:netapp:aff_c190_firmware:-:*:*:*:*:*:*:* |
| netapp | h300e_firmware | — | cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:* |
| netapp | h300s_firmware | — | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
| netapp | h410c_firmware | — | cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* |
| netapp | h410s_firmware | — | cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:* |
| netapp | h500e_firmware | — | cpe:2.3:o:netapp:h500e_firmware:-:*:*:*:*:*:*:* |
| netapp | h500s_firmware | — | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
| netapp | h610c_firmware | — | cpe:2.3:o:netapp:h610c_firmware:-:*:*:*:*:*:*:* |
| netapp | h610s_firmware | — | cpe:2.3:o:netapp:h610s_firmware:-:*:*:*:*:*:*:* |
| netapp | h615c_firmware | — | cpe:2.3:o:netapp:h615c_firmware:-:*:*:*:*:*:*:* |
| netapp | h700e_firmware | — | cpe:2.3:o:netapp:h700e_firmware:-:*:*:*:*:*:*:* |
| netapp | h700s_firmware | — | cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* |
| netapp | fas2720_firmware | — | cpe:2.3:o:netapp:fas2720_firmware:-:*:*:*:*:*:*:* |
| netapp | fas2750_firmware | — | cpe:2.3:o:netapp:fas2750_firmware:-:*:*:*:*:*:*:* |
| netapp | fas8300_firmware | — | cpe:2.3:o:netapp:fas8300_firmware:-:*:*:*:*:*:*:* |
| netapp | fas8700_firmware | — | cpe:2.3:o:netapp:fas8700_firmware:-:*:*:*:*:*:*:* |
| netapp | fas_baseboard_management_controller_a220_firmware | — | cpe:2.3:o:netapp:fas_baseboard_management_controller_a220_firmware:-:*:*:*:*:*:*:* |
| netapp | fas_baseboard_management_controller_a320_firmware | — | cpe:2.3:o:netapp:fas_baseboard_management_controller_a320_firmware:-:*:*:*:*:*:*:* |
| netapp | fas_baseboard_management_controller_a400_firmware | — | cpe:2.3:o:netapp:fas_baseboard_management_controller_a400_firmware:-:*:*:*:*:*:*:* |
| netapp | fas_baseboard_management_controller_a800_firmware | — | cpe:2.3:o:netapp:fas_baseboard_management_controller_a800_firmware:-:*:*:*:*:*:*:* |
| netapp | fas_baseboard_management_controller_c190_firmware | — | cpe:2.3:o:netapp:fas_baseboard_management_controller_c190_firmware:-:*:*:*:*:*:*:* |
| netapp | solidfire_baseboard_management_controller_firmware | — | cpe:2.3:o:netapp:solidfire_baseboard_management_controller_firmware:-:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 14.04 | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* |
| URL | Tags |
|---|---|
| https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1862840 | Issue Tracking Third Party Advisory |
| https://security.netapp.com/advisory/ntap-20200430-0004/ | Third Party Advisory |
| https://usn.ubuntu.com/usn/usn-4302-1 | Third Party Advisory |