Insyde's Security Pledge
Insyde Security Advisory 2022058
Insyde ID | Advisory Category | Impact of Vulnerability | Severity Rating | Original Date | Last Revised |
INSYDE-SA-2022058 | Software | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H | 7.8 | 11/14/2022 | 11/14/2022 |
Summary:
In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering.
Vulnerability Details
Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. It was fixed in:
Kernel 5.0: version 05.09.21
Kernel 5.1: version 05.17.21
Kernel 5.2: version 05.27.21
Kernel 5.3: version 05.36.21
Kernel 5.4: version 05.44.21
Kernel 5.5: version 05.52.21
Revision History:
Revision | Date | Description |
1.0 | 11/14/2022 | Initial Release |
- | - | - |