An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel, which also protected chipset and OEM chipset code.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-35547 | An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel, which also protected chipset and OEM chipset code. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 05 May 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-05T16:16:08.295Z
Reserved: 2022-06-06T00:00:00.000Z
Link: CVE-2022-32475
Updated: 2024-08-03T07:39:51.219Z
Status : Modified
Published: 2023-02-15T14:15:11.950
Modified: 2025-05-05T17:18:14.633
Link: CVE-2022-32475
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD