CVE-2024-21808

EUVD-2024-19420
Improper buffer restrictions in some Intel(R) VPL software before version 24.1.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.2 MEDIUM
LOCAL
HIGH
LOW
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 8.52%
Debian logo
Debian Releases
Debian Product
Codename
intel-mediasdk
bookworm
ignored
bullseye
vulnerable
onevpl-intel-gpu
bookworm
ignored
forky
26.1.2-1.1
fixed
sid
26.1.2-1.1
fixed
trixie
25.1.4-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
intel-mediasdk
focal
ignored
jammy
needs-triage
noble
needs-triage
oracular
ignored
plucky
dne
questing
dne
resolute
dne
onevpl-intel-gpu
focal
dne
jammy
needs-triage
noble
needs-triage
oracular
not-affected
plucky
not-affected
questing
not-affected
resolute
not-affected