CVE-2022-32475 Information

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel which also protected chipset and OEM chipset code.

Reference

https://www.insyde.com/security-pledge/SA-2023007 https://www.insyde.com/security-pledge

Share on: