CVE-2022-3746
published 2023-08-23CVE-2022-3746: A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to…
PriorityP426medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.17%
6.6th percentile
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.
Affected
88 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| lenovo | ideapad_1-14ijl7_firmware | < htcn31ww | htcn31ww |
| lenovo | ideapad_1-15ijl7_firmware | < htcn31ww | htcn31ww |
| lenovo | ideapad_1_14iau7_firmware | < jkcn34ww | jkcn34ww |
| lenovo | ideapad_1_14igl7_firmware | < kkcn15ww | kkcn15ww |
| lenovo | ideapad_1_15iau7_firmware | < jkcn34ww | jkcn34ww |
| lenovo | ideapad_1_15igl7_firmware | < kkcn15ww | kkcn15ww |
| lenovo | ideapad_3-14igl05_firmware | < dvcn28ww | dvcn28ww |
| lenovo | ideapad_3-14iil05_firmware | < emcn56ww | emcn56ww |
| lenovo | ideapad_3-14iml05_firmware | < dxcn44ww | dxcn44ww |
| lenovo | ideapad_3-14itl05_firmware | < gccn32ww | gccn32ww |
| lenovo | ideapad_3-14itl6_firmware | < ggcn51ww | ggcn51ww |
| lenovo | ideapad_3-15igl05_firmware | < dvcn28ww | dvcn28ww |
| lenovo | ideapad_3-15iil05_firmware | < emcn56ww | emcn56ww |
| lenovo | ideapad_3-15iml05_firmware | < dxcn44ww | dxcn44ww |
| lenovo | ideapad_3-15itl05_firmware | < gccn32ww | gccn32ww |
| lenovo | ideapad_3-15itl6_firmware | < ggcn51ww | ggcn51ww |
| lenovo | ideapad_3-17iil05_firmware | < emcn56ww | emcn56ww |
| lenovo | ideapad_3-17iml05_firmware | < dxcn44ww | dxcn44ww |
| lenovo | ideapad_3-17itl6_firmware | < ggcn51ww | ggcn51ww |
| lenovo | ideapad_3_14iau7_firmware | < jkcn34ww | jkcn34ww |
| lenovo | ideapad_3_15iau7_firmware | < jkcn34ww | jkcn34ww |
| lenovo | ideapad_3_17iau7_firmware | < jkcn34ww | jkcn34ww |
| lenovo | ideapad_5-15iil05_firmware | < dpcn58ww | dpcn58ww |
| lenovo | ideapad_5-15itl05_firmware | < fhcn70ww | fhcn70ww |
| lenovo | ideapad_5_15ial7_firmware | < jbcn27ww | jbcn27ww |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9jxg-qpc2-3vh5: A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privile
ghsa_unreviewed·2023-08-23
CVE-2022-3746 [MEDIUM] CWE-284 GHSA-9jxg-qpc2-3vh5: A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privile
A potential vulnerability was discovered in LCFC BIOS for some Lenovo consumer notebook models that could allow a local attacker with elevated privileges to cause some peripherals to work abnormally due to an exposed Embedded Controller (EC) interface.
Red Hat
kernel: drm/amdgpu: Fix use-after-free on amdgpu_bo_list mutex
vendor_redhat·2025-06-18·CVSS 7.8
CVE-2022-50035 [HIGH] kernel: drm/amdgpu: Fix use-after-free on amdgpu_bo_list mutex
kernel: drm/amdgpu: Fix use-after-free on amdgpu_bo_list mutex
In the Linux kernel, the following vulnerability has been resolved:
drm/amdgpu: Fix use-after-free on amdgpu_bo_list mutex
If amdgpu_cs_vm_handling returns r != 0, then it will unlock the
bo_list_mutex inside the function amdgpu_cs_vm_handling and again on
amdgpu_cs_parser_fini. This problem results in the following
use-after-free problem:
[ 220.280990] ------------[ cut here ]------------
[ 220.281000] refcount_t: underflow; use-after-free.
[ 220.281019] WARNING: CPU: 1 PID: 3746 at lib/refcount.c:28 refcount_warn_saturate+0xba/0x110
[ 220.281029] ------------[ cut here ]------------
[ 220.281415] CPU: 1 PID: 3746 Comm: chrome:cs0 Tainted: G W L ------- --- 5.20.0-0.rc0.20220812git7ebfc85e2cd7.10.fc38.x86_64 #1
[ 220.281421]
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-08-23
Published