CVE-2022-33986
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. DMA attacks on the parameter buffer used by the software SMI handler used by the driver VariableRuntimeDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of SMRAM. This issue was discovered by Insyde engineering during a security review. This issue is fixed in Kernel 5.4: 05.44.23 and Kernel 5.5: 05.52.23. CWE-367 CWE-367 Report at: https://www.insyde.com/security-pledge/SA-2022056
Los ataques DMA al búfer de parámetros utilizado por el controlador SMI del software VariableRuntimeDxe podrían provocar un ataque TOCTOU. Los ataques DMA al búfer de parámetros utilizado por el controlador SMI de software utilizado por el controlador VariableRuntimeDxe podrían provocar un ataque TOCTOU al controlador SMI y provocar la corrupción de SMRAM. Este problema fue descubierto por la ingeniería de Insyde durante una revisión de seguridad. Este problema se solucionó en Kernel 5.4: 05.44.23 y Kernel 5.5: 05.52.23. CWE-367 Informe CWE-367 en: https://www.insyde.com/security-pledge/SA-2022056
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-06-18 CVE Reserved
- 2022-11-14 CVE Published
- 2024-06-06 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition
CAPEC
References (2)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.insyde.com/security-pledge | 2022-11-18 | |
https://www.insyde.com/security-pledge/SA-2022056 | 2022-11-18 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Insyde Search vendor "Insyde" | Kernel Search vendor "Insyde" for product "Kernel" | >= 5.4 < 5.4.05.44.23 Search vendor "Insyde" for product "Kernel" and version " >= 5.4 < 5.4.05.44.23" | - |
Affected
| ||||||
Insyde Search vendor "Insyde" | Kernel Search vendor "Insyde" for product "Kernel" | >= 5.5 < 5.5.05.52.23 Search vendor "Insyde" for product "Kernel" and version " >= 5.5 < 5.5.05.52.23" | - |
Affected
|