CVE-2022-29276

SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was discovered by Insyde during security review. It was fixed in: Kernel 5.0: version 05.09.18 Kernel 5.1: version 05.17.18 Kernel 5.2: version 05.27.18 Kernel 5.3: version 05.36.18 Kernel 5.4: version 05.44.18 Kernel 5.5: version 05.52.18 https://www.insyde.com/security-pledge/SA-2022059
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*

History

29 Nov 2022, 14:28

Type Values Removed Values Added
CWE CWE-787
First Time Insyde kernel
Insyde
References (MISC) https://www.insyde.com/security-pledge/SA-2022059 - (MISC) https://www.insyde.com/security-pledge/SA-2022059 - Vendor Advisory
References (MISC) https://www.insyde.com/security-pledge - (MISC) https://www.insyde.com/security-pledge - Vendor Advisory
CPE cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2

16 Nov 2022, 00:09

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-15 22:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-29276

Mitre link : CVE-2022-29276

CVE.ORG link : CVE-2022-29276


JSON object : View

Products Affected

insyde

  • kernel
CWE
CWE-787

Out-of-bounds Write