CVE-2019-14615 is an information-disclosure vulnerability affecting certain Intel processors with Gen9 or Gen10 integrated Processor Graphics. The GPU context-switch handling did not clear certain user-visible state, allowing data associated with one GPU task to remain accessible to a subsequently scheduled task. This represents insufficient isolation of GPU execution contexts.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2019-14615, a vulnerability in Intel integrated GPUs (iGPUs) that allows information leakage via uninitialized GPU memory. The exploit demonstrates how an attacker process can read data left in the Shared Local Memory (SLM) of the GPU by a victim process, due to improper memory clearing by the Intel graphics driver. The PoC is structured as follows: - The 'demo/SLM_Leak' directory contains scripts and OpenCL kernels for the attack. 'run_attacker.sh' launches the attacker process, which repeatedly reads SLM data using the 'slm_attacker.cl' kernel. 'run_victim.sh' launches the victim process, which writes data to SLM using 'slm_victim.cl'. - The 'demo/util' directory contains a C++ OpenCL host program ('main.cpp') and supporting files to compile and run the OpenCL kernels. - The exploit requires two processes: one acting as the victim (writing to SLM) and one as the attacker (reading from SLM). The attacker can observe data remnants left by the victim, demonstrating the information leak. - The repository includes installation scripts for OpenCL dependencies and detailed documentation in the README files. This PoC is local-only and requires specific hardware and software configuration. It does not provide remote exploitation or privilege escalation, but demonstrates a real risk of sensitive data leakage between GPU-using processes on affected Intel hardware.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Linux kernel vulnerability referenced by the Red Hat kernel security advisory.
A Linux kernel vulnerability addressed by this kernel-rt security update; no technical details are provided in the advisory.
Intel Gen9/Gen10 GPU context-switch information disclosure mitigated in the i915 driver.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.