CVE-2022-29278

Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory. This issue was discovered by Insyde during security review. Fixed in: Kernel 5.1: Version 05.17.23 Kernel 5.2: Version 05.27.23 Kernel 5.3: Version 05.36.23 Kernel 5.4: Version 05.44.23 Kernel 5.5: Version 05.52.23 https://www.insyde.com/security-pledge/SA-2022061
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*

History

29 Nov 2022, 14:27

Type Values Removed Values Added
CPE cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:*
First Time Insyde kernel
Insyde
CWE CWE-754
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.2
References (MISC) https://www.insyde.com/security-pledge - (MISC) https://www.insyde.com/security-pledge - Vendor Advisory
References (MISC) https://www.insyde.com/security-pledge/SA-2022061 - (MISC) https://www.insyde.com/security-pledge/SA-2022061 - Vendor Advisory

16 Nov 2022, 00:09

Type Values Removed Values Added
New CVE

Information

Published : 2022-11-15 22:15

Updated : 2023-12-10 14:35


NVD link : CVE-2022-29278

Mitre link : CVE-2022-29278

CVE.ORG link : CVE-2022-29278


JSON object : View

Products Affected

insyde

  • kernel
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions