An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The SMI handler for the FwBlockServiceSmm driver uses an untrusted pointer as the location to copy data to an attacker-specified buffer, leading to information disclosure.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-09-22T17:07:10
Updated: 2024-08-03T09:44:22.247Z
Reserved: 2022-07-15T00:00:00
Link: CVE-2022-35894
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-09-22T18:15:10.200
Modified: 2024-11-21T07:11:53.757
Link: CVE-2022-35894
Redhat
No data.