Insyde Security Advisory 2022058

Insyde ID Advisory Category Impact of Vulnerability Severity Rating Original Date Last Revised
INSYDE-SA-2022058 Software CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H 7.8 11/14/2022 11/14/2022


In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering.

Vulnerability Details


Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. It was fixed in:

Kernel 5.0: version 05.09.21
Kernel 5.1: version 05.17.21
Kernel 5.2: version 05.27.21
Kernel 5.3: version 05.36.21
Kernel 5.4: version 05.44.21
Kernel 5.5: version 05.52.21

Revision History:

Revision Date Description
1.0 11/14/2022 Initial Release
- - -

Return to Insyde's Security Pledge