In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. It was fixed in: Kernel 5.0: version 05.09.21 Kernel 5.1: version 05.17.21 Kernel 5.2: version 05.27.21 Kernel 5.3: version 05.36.21 Kernel 5.4: version 05.44.21 Kernel 5.5: version 05.52.21 https://www.insyde.com/security-pledge/SA-2022058
2022-11-15T21:15:36.607
2025-04-30T15:15:52.093
Modified
CVSSv3.1: 8.2 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | insyde | kernel | ≤ 5.0.05.09.21 | Yes |
Operating System | insyde | kernel | < 5.1.05.17.21 | Yes |
Operating System | insyde | kernel | < 5.2.05.27.21 | Yes |
Operating System | insyde | kernel | < 5.3.05.36.21 | Yes |
Operating System | insyde | kernel | < 5.4.05.44.21 | Yes |
Operating System | insyde | kernel | < 5.5.05.52.21 | Yes |