CVE-2020-12912 describes a potential vulnerability in the AMD extension to the Linux "hwmon" service, specifically affecting the AMD energy_driver_for_linux. This flaw could allow an attacker to leverage the Linux-based Running Average Power Limit (RAPL) interface for various side-channel attacks. Rated 5.5 MEDIUM, the vulnerability requires local, low-privileged access (AV:L/PR:L) and could lead to high confidentiality impact (C:H) without affecting integrity or availability. While there is no evidence of active exploitation, public exploit code, or KEV listing, AMD has addressed this by requiring privileged access to the RAPL interface.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:amd:energy_driver_for_linux:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.