CVE-2023-39929

EUVD-2023-43627
Uncontrolled search path in some Libva software maintained by Intel(R) before version 2.20.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.7 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
intellibva
𝑥
< 2.20.0
ADP
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libva
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
mantic
ignored
noble
needs-triage
oracular
needs-triage
trusty
ignored
xenial
needs-triage
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libva-devel
suse enterprise server 12 SP5
2.20.0-3.3.4
fixed
suse enterprise server 15 SP2
2.20.0-150200.4.3.1
fixed
suse enterprise server 15 SP3
2.20.0-150300.3.3.1
fixed
suse enterprise server 15 SP4
2.20.0-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.20.0-150500.3.5.1
fixed
libva-drm2
suse enterprise server 12 SP5
2.20.0-3.3.4
fixed
suse enterprise server 15 SP2
2.20.0-150200.4.3.1
fixed
suse enterprise server 15 SP3
2.20.0-150300.3.3.1
fixed
suse enterprise server 15 SP4
2.20.0-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.20.0-150500.3.5.1
fixed
libva-wayland2
suse enterprise server 15 SP2
2.20.0-150200.4.3.1
fixed
suse enterprise server 15 SP3
2.20.0-150300.3.3.1
fixed
suse enterprise server 15 SP4
2.20.0-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.20.0-150500.3.5.1
fixed
libva-x11-2
suse enterprise server 12 SP5
2.20.0-3.3.4
fixed
suse enterprise server 15 SP2
2.20.0-150200.4.3.1
fixed
suse enterprise server 15 SP3
2.20.0-150300.3.3.1
fixed
suse enterprise server 15 SP4
2.20.0-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.20.0-150500.3.5.1
fixed
libva2
suse enterprise server 12 SP5
2.20.0-3.3.4
fixed
suse enterprise server 15 SP2
2.20.0-150200.4.3.1
fixed
suse enterprise server 15 SP3
2.20.0-150300.3.3.1
fixed
suse enterprise server 15 SP4
2.20.0-150400.3.5.1
fixed
suse enterprise server 15 SP5
2.20.0-150500.3.5.1
fixed