Описание
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel, which also protected chipset and OEM chipset code.
Ссылки
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия от 5.0 (включая) до 5.2.05.27.27 (исключая)Версия от 5.3 (включая) до 5.3.05.36.27 (исключая)Версия от 5.4 (включая) до 5.4.05.44.27 (исключая)Версия от 5.5 (включая) до 5.5.05.52.27 (исключая)
Одно из
cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*
cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*
EPSS
Процентиль: 15%
0.00049
Низкий
7 High
CVSS3
Дефекты
CWE-367
CWE-367
Связанные уязвимости
CVSS3: 7
github
почти 3 года назад
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel, which also protected chipset and OEM chipset code.
EPSS
Процентиль: 15%
0.00049
Низкий
7 High
CVSS3
Дефекты
CWE-367
CWE-367