---
title: "CVE-2020-8696\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2020-8696?format=md
keywords: index, follow
---

# CVE-2020-8696

Publication date 10 November 2020

Last updated 25 August 2025

---

Ubuntu priority

**Low**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

## Cvss 3 Severity Score

**2.8 · Low**

[Score breakdown](https://ubuntu.com/security/CVE-2020-8696?format=md#impact-score)

Toggle side navigation

## Description

Improper removal of sensitive information before storage or transfer in
some Intel(R) Processors may allow an authenticated user to potentially
enable information disclosure via local access.

### From the Ubuntu Security Team

Ezra Caltum, Joseph Nuzman, Nir Shildan and Ofir Joseff discovered
that some Intel(R) Processors did not properly remove sensitive
information before storage or transfer in some situations. A local
attacker could possibly use this to expose sensitive information.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| intel-microcode | 20.10 groovy | Fixed 3.20210216.0ubuntu0.20.10.1 |
| 20.04 LTS focal | Fixed 3.20210216.0ubuntu0.20.04.1 |
| 19.10 eoan | Ignored end of life |
| 18.04 LTS bionic | Fixed 3.20210216.0ubuntu0.18.04.1 |
| 16.04 LTS xenial | Fixed 3.20201110.0ubuntu0.16.04.1 |
| 14.04 LTS trusty | Fixed 3.20201110.0ubuntu0.14.04.1  Ubuntu Pro |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

### Get expanded security coverage with Ubuntu Pro

Reduce your average CVE exposure time from 98 days to 1 day with expanded CVE patching, ten-years security maintenance and optional support for the full stack of open-source applications. Free for personal use.

[Get Ubuntu Pro](https://ubuntu.com/pro)
[30-day free trial](https://ubuntu.com/pro/free-trial)

## Severity score breakdown

CVSS version:
CVSS v3.0

**Base score**

2.8 · Low

* Base metrics

  | Parameter | Value |
  | --- | --- |
  | Attack vector | Local |
  | Attack complexity | High |
  | Privileges required | Low |
  | User interaction | None |
  | Scope | Changed |
  | Confidentiality impact | Low |
  | Integrity impact | None |
  | Availability impact | None |
* Scores

  | Parameter | Value |
  | --- | --- |
  | Base score | 2.8 · Low |
  | Exploitability score | - |
  | Impact score | - |

**Vector:** CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:L/I:N/A:N

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-8696)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-8696)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2020-8696)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2020-8696)

### Related Ubuntu Security Notices (USN)

+ [USN-4628-1](https://usn.ubuntu.com/USN-4628-1)
+ Intel Microcode vulnerabilities
+ 11 November 2020

+ [USN-4628-3](https://usn.ubuntu.com/USN-4628-3)
+ Intel Microcode vulnerabilities
+ 17 May 2021

### Other references

* <https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00381.html>
* <https://www.cve.org/CVERecord?id=CVE-2020-8696>
