Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-29275


In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. It was fixed in: Kernel 5.0: version 05.09.21 Kernel 5.1: version 05.17.21 Kernel 5.2: version 05.27.21 Kernel 5.3: version 05.36.21 Kernel 5.4: version 05.44.21 Kernel 5.5: version 05.52.21 https://www.insyde.com/security-pledge/SA-2022058


Published

2022-11-15T21:15:36.607

Last Modified

2025-04-30T15:15:52.093

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.2 (HIGH)

Weaknesses
  • Type: Primary
    CWE-119
  • Type: Secondary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System insyde kernel ≤ 5.0.05.09.21 Yes
Operating System insyde kernel < 5.1.05.17.21 Yes
Operating System insyde kernel < 5.2.05.27.21 Yes
Operating System insyde kernel < 5.3.05.36.21 Yes
Operating System insyde kernel < 5.4.05.44.21 Yes
Operating System insyde kernel < 5.5.05.52.21 Yes

References