CVE-2022-30773

MEDIUM

IhisiSmm <5.4.23, <5.5.23 - Memory Corruption

Title source: llm
STIX 2.1

Description

DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). This issue was discovered by Insyde engineering. This issue is fixed in Kernel 5.4: 05.44.23 and Kernel 5.5: 05.52.23. CWE-367

References (2)

Core 2

Scores

CVSS v3 6.4
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-367
Status published
Products (1)
insyde/kernel 5.4 - 5.4.05.44.23
Published Nov 14, 2022
Tracked Since Feb 18, 2026