Description
In the Linux kernel, the following vulnerability has been resolved: platform/x86: think-lmi: Fix password opcode ordering for workstations The Lenovo workstations require the password opcode to be run before the attribute value is changed (if Admin password is enabled). Tested on some Thinkpads to confirm they are OK with this order too.
References (3)
Core 3
Scores
CVSS v3
7.8
EPSS
0.0023
EPSS Percentile
14.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
Status
published
Products (12)
linux/Kernel
5.17.0 - 6.6.55linux
linux/Kernel
6.7.0 - 6.7.7linux
Linux/Linux
< 5.17
Linux/Linux
5.17
Linux/Linux
6.6.55 - 6.6.*
Linux/Linux
6.7.7 - 6.7.*
Linux/Linux
6.8
Linux/Linux
640a5fa50a42b99bfa2a0ec51b4ea9591d9bd055 - 2bfbe1e0aed00ba51d58573c79452fada3f62ed4
Linux/Linux
640a5fa50a42b99bfa2a0ec51b4ea9591d9bd055 - 2deb10a99671afda30f834e95e5b992a805bba6a
Linux/Linux
640a5fa50a42b99bfa2a0ec51b4ea9591d9bd055 - 6f7d0f5fd8e440c3446560100ac4ff9a55eec340
... and 2 more
Published
Apr 17, 2024
Tracked Since
Feb 18, 2026