HIGH
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5
Published Sep 23, 2022
8.2
HIGHCVSS 3.1
EPSS 0.23%
Description
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An SMM memory corruption vulnerability in the FvbServicesRuntimeDxe driver allows an attacker to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Affected products
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://binarly.io/advisories/BRLY-2022-026/index.html x_refsource_MISCThird Party Advisory
- https://www.insyde.com/security-pledge x_refsource_MISCVendor Advisory
- https://www.insyde.com/security-pledge/SA-2022035 x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://binarly.io/advisories/BRLY-2022-026/index.html | x_refsource_MISCThird Party Advisory | |
| https://www.insyde.com/security-pledge | x_refsource_MISCVendor Advisory | |
| https://www.insyde.com/security-pledge/SA-2022035 | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Sep 23, 2022
Updated May 5, 2025
Reserved Jul 15, 2022
Link CVE-2022-35893
CISA Vulnrichment
Updated Apr 23, 2025