CVE-2019-14615

MEDIUM

Intel(R) Processors - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2019-14615. PoCs published by HE-Wenjian.

AI-analyzed exploit summary This repository contains a functional proof-of-concept exploit for CVE-2019-14615, demonstrating information leakage from Intel iGPUs via uninitialized data in Shared Local Memory (SLM). The PoC includes scripts and OpenCL code to simulate an attacker leaking data from a victim process.

Description

Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access.

Exploits (1)

nomisec WORKING POC 56 stars
by HE-Wenjian · poc
https://github.com/HE-Wenjian/iGPU-Leak

This repository contains a functional proof-of-concept exploit for CVE-2019-14615, demonstrating information leakage from Intel iGPUs via uninitialized data in Shared Local Memory (SLM). The PoC includes scripts and OpenCL code to simulate an attacker leaking data from a victim process.

Classification
Working Poc 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: Intel Integrated GPUs (3rd to 10th Gen Core processors)
No auth needed
Prerequisites: Intel CPU with integrated GPU · 64-bit Ubuntu 16.04/18.04 · OpenCL runtime
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (19)

Core 19
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4287-2/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4253-1/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4254-1/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4255-1/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4255-2/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4253-2/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4254-2/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4285-1/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4287-1/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4286-2/
Mailing List mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/03/msg00001.html
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4284-1/
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4286-1/
Vendor Advisory x_refsource_confirm
https://support.apple.com/kb/HT211100
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2020/Mar/31

Scores

CVSS v3 5.5
EPSS 0.0450
EPSS Percentile 89.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

Status published
Products (50)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 19.10
intel/atom_e3805
intel/atom_e3805_firmware
intel/atom_e3815
intel/atom_e3815_firmware
intel/atom_e3825
intel/atom_e3825_firmware
... and 40 more
Published Jan 17, 2020
Tracked Since Feb 18, 2026