Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x6hx-69p4-ccw5

Опубликовано: 10 фев. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 4.6

Описание

A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.

A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.

EPSS

Процентиль: 2%
0.00121
Низкий

4.6 Medium

CVSS4

Дефекты

CWE-367

Связанные уязвимости

nvd
6 месяцев назад

A Time-of-check time-of-use (TOCTOU) race condition in the SMM communications buffer could allow a privileged attacker to bypass input validation and perform an out of bounds read or write, potentially resulting in loss of confidentiality, integrity, or availability.

CVSS3: 4.2
fstec
6 месяцев назад

Уязвимость буфера связи SMM микропрограммного обеспечения графических процессоров AMD, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации

EPSS

Процентиль: 2%
0.00121
Низкий

4.6 Medium

CVSS4

Дефекты

CWE-367