CVE-2022-37020
published 2024-06-10CVE-2022-37020: Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP…
PriorityP430medium6.8CVSS 3.1
AVLACLPRNUINSUCNIHAL
EPSS
0.18%
7.4th percentile
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| hp | elite_slice_firmware | < 00.02.64 | 00.02.64 |
| hp | elite_slice_for_meeting_rooms_firmware | < 00.02.64 | 00.02.64 |
| hp | elitebook_1040_g3_firmware | < 01.62 | 01.62 |
| hp | elitebook_820_g3_firmware | < 01.62 | 01.62 |
| hp | elitebook_828_g3_firmware | < 01.62 | 01.62 |
| hp | elitebook_840_g3_firmware | < 01.62 | 01.62 |
| hp | elitebook_848_g3_firmware | < 01.62 | 01.62 |
| hp | elitebook_850_g3_firmware | < 01.62 | 01.62 |
| hp | elitebook_folio_g1_firmware | < 01.62 | 01.62 |
| hp | elitedesk_800_35w_g2_desktop_mini_pc_firmware | < 00.02.63 | 00.02.63 |
| hp | elitedesk_800_65w_g2_desktop_mini_pc_firmware | < 00.02.63 | 00.02.63 |
| hp | mp9_g2_retail_system_firmware | < 02.63 | 02.63 |
| hp | probook_440_g3_firmware | < 1.62 | 1.62 |
| hp | probook_446_g3_firmware | < 1.62 | 1.62 |
| hp | probook_470_g3_firmware | < 1.62 | 1.62 |
| hp | probook_640_g2_firmware | < 1.62 | 1.62 |
| hp | probook_650_g2_firmware | < 1.62 | 1.62 |
| hp | rp9_g1_retail_system_firmware | < 02.64 | 02.64 |
| hp | z238_microtower_workstation_firmware | < 01.91 | 01.91 |
| hp | z240_small_form_factor_workstation_firmware | < 01.91 | 01.91 |
| hp | z240_tower_workstation_firmware | < 01.91 | 01.91 |
| hp | z2_mini_g3_workstation_firmware | < 01.91 | 01.91 |
| hp | zbook_15_g3_firmware | < 1.62 | 1.62 |
| hp | zbook_15u_g3_firmware | < 1.62 | 1.62 |
| hp | zbook_17_g3_firmware | < 1.62 | 1.62 |
CVSS provenance
nvdv3.16.8MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:L
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-96w6-6hm2-2gpw: Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code exec
ghsa_unreviewed·2024-06-11
CVE-2022-37020 [MEDIUM] CWE-120 GHSA-96w6-6hm2-2gpw: Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code exec
Potential vulnerabilities have been identified in the system BIOS for certain HP PC products, which might allow escalation of privileges and code execution. HP is releasing firmware updates to mitigate the potential vulnerabilities.
Red Hat
kernel: scsi: mpt3sas: Fix possible resource leaks in mpt3sas_transport_port_add()
vendor_redhat·2025-10-07·CVSS 5.5
CVE-2022-50532 [MEDIUM] CWE-476 kernel: scsi: mpt3sas: Fix possible resource leaks in mpt3sas_transport_port_add()
kernel: scsi: mpt3sas: Fix possible resource leaks in mpt3sas_transport_port_add()
In the Linux kernel, the following vulnerability has been resolved:
scsi: mpt3sas: Fix possible resource leaks in mpt3sas_transport_port_add()
In mpt3sas_transport_port_add(), if sas_rphy_add() returns error,
sas_rphy_free() needs be called to free the resource allocated in
sas_end_device_alloc(). Otherwise a kernel crash will happen:
Unable to handle kernel NULL pointer dereference at virtual address 0000000000000108
CPU: 45 PID: 37020 Comm: bash Kdump: loaded Tainted: G W 6.1.0-rc1+ #189
pstate: 60000005 (nZCv daif -PAN -UAO -TCO -DIT -SSBS BTYPE=--)
pc : device_del+0x54/0x3d0
lr : device_del+0x37c/0x3d0
Call trace:
device_del+0x54/0x3d0
attribute_container_class_device_del+0x28/0x38
transport_remove_clas
No detection rules found.
No public exploits indexed.
2024-06-10
Published