Description


DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). This issue was discovered by Insyde engineering. This issue is fixed in Kernel 5.4: 05.44.23 and Kernel 5.5: 05.52.23. CWE-367

Related CPE's


a

insyde

kernel

2

Weaknesses



CWE-367

134c704f-9b21-4f2e-91b3-4a467353bcc0

Secondary

CWE-367

CVSS impact metrics


CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

6.4 · Medium

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-11-14T21:15:13.373Z

3 years ago

Last modified

2025-04-30T18:15:16.970Z

11 months ago