Vulnerability CVE-2022-32475


Published: 2023-02-15

Description:
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel, which also protected chipset and OEM chipset code.

 References:
https://www.insyde.com/security-pledge/SA-2023007
https://www.insyde.com/security-pledge

Copyright 2026, cxsecurity.com

 

Back to Top