CVE-2022-30283
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an attacker to cause SMRAM corruption and escalation of privileges The UsbCoreDxe module creates a working buffer for USB transactions outside of SMRAM. The code which uses can be inside of SMM, making the working buffer untrusted input. The buffer can be corrupted by DMA transfers. The SMM code code attempts to sanitize pointers to ensure all pointers refer to the working buffer, but when a pointer is not found in the list of pointers to sanitize, the current action is not aborted, leading to undefined behavior. This issue was discovered by Insyde engineering based on the general description provided by Intel's iSTARE group. Fixed in: Kernel 5.0: Version 05.09. 21 Kernel 5.1: Version 05.17.21 Kernel 5.2: Version 05.27.21 Kernel 5.3: Version 05.36.21 Kernel 5.4: Version 05.44.21 Kernel 5.5: Version 05.52.21 https://www.insyde.com/security-pledge/SA-2022063
En UsbCoreDxe, la manipulación del contenido del búfer de trabajo USB usando DMA mientras ciertas transacciones USB están en proceso conduce a un problema TOCTOU que podría ser utilizado por un atacante para causar corrupción SMRAM y escalada de privilegios. El módulo UsbCoreDxe crea un búfer de trabajo para transacciones USB fuera de SMRAM. El código que se utiliza puede estar dentro de SMM, lo que hace que el búfer de trabajo sea una entrada no confiable. El búfer puede resultar dañado por las transferencias DMA. El código SMM intenta sanitizar los punteros para garantizar que todos los punteros se refieran al búfer de trabajo, pero cuando no se encuentra un puntero en la lista de punteros para sanitizar la acción actual no se cancela, lo que genera un comportamiento indefinido. Este problema fue descubierto por ingeniería de Insyde basándose en la descripción general proporcionada por el grupo iSTARE de Intel. Corregido en: Kernel 5.0: Versión 05.09. 21 Kernel 5.1: Versión 05.17.21 Kernel 5.2: Versión 05.27.21 Kernel 5.3: Versión 05.36.21 Kernel 5.4: Versión 05.44.21 Kernel 5.5: Versión 05.52.21
https://www.insyde.com/security-pledge/SA-2022063
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-05-04 CVE Reserved
- 2022-11-15 CVE Published
- 2024-06-07 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.insyde.com/security-pledge | 2022-11-23 | |
https://www.insyde.com/security-pledge/SA-2022063 | 2022-11-23 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Insyde Search vendor "Insyde" | Kernel Search vendor "Insyde" for product "Kernel" | >= 5.0 < 5.0.05.09.21 Search vendor "Insyde" for product "Kernel" and version " >= 5.0 < 5.0.05.09.21" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Kernel Search vendor "Insyde" for product "Kernel" | >= 5.1 < 5.1.05.17.21 Search vendor "Insyde" for product "Kernel" and version " >= 5.1 < 5.1.05.17.21" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Kernel Search vendor "Insyde" for product "Kernel" | >= 5.2 < 5.2.05.27.21 Search vendor "Insyde" for product "Kernel" and version " >= 5.2 < 5.2.05.27.21" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Kernel Search vendor "Insyde" for product "Kernel" | >= 5.3 < 5.3.05.36.21 Search vendor "Insyde" for product "Kernel" and version " >= 5.3 < 5.3.05.36.21" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Kernel Search vendor "Insyde" for product "Kernel" | >= 5.4 < 5.4.05.44.21 Search vendor "Insyde" for product "Kernel" and version " >= 5.4 < 5.4.05.44.21" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Kernel Search vendor "Insyde" for product "Kernel" | >= 5.5 < 5.5.05.52.21 Search vendor "Insyde" for product "Kernel" and version " >= 5.5 < 5.5.05.52.21" | - |
Affected
|