CVE-2022-23829
published 2024-06-18CVE-2022-23829: A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode…
PriorityP339high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
EPSS
0.20%
9.5th percentile
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.
Affected
24 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | 1st_gen_amd_epyc_processors | — | — |
| amd | 2nd_gen_amd_epyc_processors | — | — |
| amd | 3rd_gen_amd_epyc_processors | — | — |
| amd | amd_athlon_3000_series_mobile_processors_with_radeon_graphics | — | — |
| amd | amd_epyc_embedded_3000 | — | — |
| amd | amd_epyc_embedded_7002 | — | — |
| amd | amd_epyc_embedded_7003 | — | — |
| amd | amd_ryzen_3000_series_desktop_processors | — | — |
| amd | amd_ryzen_3000_series_mobile_processor_2nd_gen_amd_ryzen_mobile_processor_with_r | — | — |
| amd | amd_ryzen_4000_series_desktop_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_4000_series_mobile_processors | — | — |
| amd | amd_ryzen_5000_series_desktop_processors | — | — |
| amd | amd_ryzen_5000_series_mobile_processors | — | — |
| amd | amd_ryzen_5000_series_mobile_processors_with_radeon_graphics | — | — |
| amd | amd_ryzen_6000_series_mobile_processors_and_workstations | — | — |
| amd | amd_ryzen_7000_series_desktop_processors | — | — |
| amd | amd_ryzen_threadripper_pro_processor | — | — |
| amd | amd_ryzen_threadripper_pro_processors_5900_wx-series | — | — |
| amd | amd_ryzentm_embedded_5000 | — | — |
| amd | amd_ryzentm_embedded_r1000 | — | — |
| amd | amd_ryzentm_embedded_r2000 | — | — |
| amd | amd_ryzentm_embedded_v1000 | — | — |
| amd | amd_ryzentm_embedded_v2000 | — | — |
| amd | amd_ryzentm_embedded_v3000 | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
vendor_redhat8.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-624f-w3rg-939c: A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Managem
ghsa_unreviewed·2024-06-18
CVE-2022-23829 [HIGH] CWE-284 GHSA-624f-w3rg-939c: A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Managem
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.
Red Hat
hw: amd: SPI protection feature may result in a potential arbitrary code execution.
vendor_redhat·2024-06-11·CVSS 8.2
CVE-2022-23829 [HIGH] hw: amd: SPI protection feature may result in a potential arbitrary code execution.
hw: amd: SPI protection feature may result in a potential arbitrary code execution.
A potential weakness in AMD SPI protection features may allow a malicious attacker with Ring0 (kernel mode) access to bypass the native System Management Mode (SMM) ROM protections.
A flaw was found in AMD SPI. The protection features may allow a malicious attacker with Ring0 kernel mode access to bypass the native System Management Mode (SMM) ROM protections.
Mitigation: Platform BIOS changes are needed to enable AMD ROM Armor.
Please contact OEM supplier for the BIOS update.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8)
No detection rules found.
No public exploits indexed.
2024-06-18
Published