CVE-2022-32267

DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM corruption (a TOCTOU attack) DMA transactions which are targeted at input buffers used for the software SMI handler used by the SmmResourceCheckDxe driver could cause SMRAM corruption through a TOCTOU attack... This issue was discovered by Insyde engineering. Fixed in kernel Kernel 5.2: 05.27.23. Kernel 5.3: 05.36.23. Kernel 5.4: 05.44.23. Kernel 5.5: 05.52.23 https://www.insyde.com/security-pledge/SA-2022046
References
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:a:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:a:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:a:insyde:kernel:*:*:*:*:*:*:*:*

Information

Published : 2022-11-14 16:15

Updated : 2022-11-18 08:01


NVD link : CVE-2022-32267

Mitre link : CVE-2022-32267


JSON object : View

CWE
CWE-367

Time-of-check Time-of-use (TOCTOU) Race Condition

Advertisement

dedicated server usa

Products Affected

insyde

  • kernel