CVE-2022-32266
Last modified
CVE-2022-32266 is a medium-severity vulnerability rated 6.4/10 on the CVSS scale. DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields. DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields. DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields. The attack would require detailed knowledge of the PCD database contents on the current platform. This issue was discovered by Insyde engineering during a security review. This issue is fixed in Kernel 5.3: 05.36.23, Kernel 5.4: 05.44.23, Kernel 5.5: 05.52.23. Kernel 5.2 is unaffected. CWE-787 An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the parameter buffer that is used by a software SMI handler (used by the PcdSmmDxe driver) could lead to a TOCTOU race-condition attack on the SMI handler, and lead to corruption of other ACPI fields and adjacent memory fields. The attack would require detailed knowledge of the PCD database contents on the current platform.
Metrics
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Insyde | Kernel | >= 5.3, < 5.3.05.36.23 |
| Insyde | Kernel | >= 5.4, < 5.4.05.44.23 |
| Insyde | Kernel | >= 5.5, < 5.5.05.52.23 |
References
- https://www.insyde.com/security-pledgeVendor Advisory
- https://www.insyde.com/security-pledge/SA-2022045Vendor Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
- https://www.insyde.com/security-pledge/SA-2022045Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-32266?
How severe is CVE-2022-32266?
How do I fix CVE-2022-32266?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-32260A vulnerability has been identified in SINEMA Remote Connect…9.8
- CVE-2022-32261A vulnerability has been identified in SINEMA Remote Connect…7.5
- CVE-2022-32262A vulnerability has been identified in SINEMA Remote Connect…9.8
- CVE-2022-32263Pexip Infinity before 28.1 allows remote attackers to trigge…7.5
- CVE-2022-32264sys/netinet/tcp_timer.h in FreeBSD before 7.0 contains a den…7.5
- CVE-2022-32265qDecoder before 12.1.0 does not ensure that the percent char…5.3
- CVE-2022-32267DMA transactions which are targeted at input buffers used fo…6.4
- CVE-2022-32268StarWind SAN and NAS v0.2 build 1914 allow remote code execu…8.8
- CVE-2022-32269In Real Player 20.0.8.310, the G2 Control allows injection o…9.8
- CVE-2022-32270In Real Player 20.0.7.309 and 20.0.8.310, external::Import()…9.8
- CVE-2022-32271In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbi…9.6
- CVE-2022-32272OPSWAT MetaDefender Core before 5.1.2, MetaDefender ICAP bef…9.8
Are you affected by CVE-2022-32266?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
