Insyde Kernel vulnerabilities

33 known vulnerabilities affecting insyde/kernel.

Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH18MEDIUM14

Vulnerabilities

Page 2 of 2
CVE-2022-33908HIGHCVSS 7.0≥ 5.2, < 5.2.05.27.25≥ 5.3, < 5.3.05.36.25+2 more2022-11-15
CVE-2022-33908 [HIGH] CWE-367 CVE-2022-33908: DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the SdHostDriver driver could cause SMRAM corruption through a TOCTOU attack. This issue was discovered b
nvd
CVE-2022-33985HIGHCVSS 7.0≥ 5.2, < 5.2.05.27.25≥ 5.3, < 5.3.05.36.25+2 more2022-11-15
CVE-2022-33985 [HIGH] CWE-367 CVE-2022-33985: DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the NvmExpressDxe driver could cause SMRAM corruption through a TOCTOU attack. This issue was discovere
nvd
CVE-2022-33986MEDIUMCVSS 6.4≥ 5.4, < 5.4.05.44.23≥ 5.5, < 5.5.05.52.232022-11-15
CVE-2022-33986 [MEDIUM] CWE-367 CVE-2022-33986: DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead t DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. DMA attacks on the parameter buffer used by the software SMI handler used by the driver VariableRuntimeDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of SMRAM. This issue was discovered by Insyde enginee
nvd
CVE-2022-33906MEDIUMCVSS 6.4≥ 5.2, < 5.2.05.27.23≥ 5.3, < 5.3.05.36.23+2 more2022-11-15
CVE-2022-33906 [MEDIUM] CWE-367 CVE-2022-33906: DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI han DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the FwBlockServiceSmm driver could cause SMRAM corruption through a TOCTOU attack. This issue was
nvd
CVE-2022-32267MEDIUMCVSS 6.4≥ 5.2, < 5.2.05.27.23≥ 5.3, < 5.3.05.36.23+2 more2022-11-15
CVE-2022-32267 [MEDIUM] CWE-367 CVE-2022-32267: DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI h DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM corruption (a TOCTOU attack) DMA transactions which are targeted at input buffers used for the software SMI handler used by the SmmResourceCheckDxe driver could cause SMRAM corruption through a TOCTOU attack... This issue was discov
nvd
CVE-2022-30774MEDIUMCVSS 6.4≥ 5.2, < 5.2.05.27.29≥ 5.3, < 5.3.05.36.25+2 more2022-11-15
CVE-2022-30774 [MEDIUM] CWE-367 CVE-2022-30774: DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parame DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack) DMA attacks on the parameter buffer used by the PnpSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack) . This
nvd
CVE-2022-31243MEDIUMCVSS 6.4≥ 5.2, < 5.2.05.27.21≥ 5.3, < 5.3.05.36.21+2 more2022-11-15
CVE-2022-31243 [MEDIUM] CWE-367 CVE-2022-31243: Update description and links DMA transactions which are targeted at input buffers used for the softw Update description and links DMA transactions which are targeted at input buffers used for the software SMI handler used by the FvbServicesRuntimeDxe driver could cause SMRAM corruption through a TOCTOU attack.. "DMA transactions which are targeted at input buffers used for the software SMI handler used by the FvbServicesRuntimeDxe driver could caus
nvd
CVE-2022-33982MEDIUMCVSS 6.4≥ 5.2, < 5.2.05.27.23≥ 5.3, < 5.3.05.36.23+2 more2022-11-14
CVE-2022-33982 [MEDIUM] CWE-367 CVE-2022-33982: DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a DMA attacks on the parameter buffer used by the Int15ServiceSmm software SMI handler could lead to a TOCTOU attack on the SMI handler and lead to corruption of SMRAM. DMA attacks on the parameter buffer used by the software SMI handler used by the driver Int15ServiceSmm could lead to a TOCTOU attack on the SMI handler and lead to corruption of SMRAM
nvd
CVE-2022-32266MEDIUMCVSS 6.4≥ 5.3, < 5.3.05.36.23≥ 5.4, < 5.4.05.44.23+1 more2022-11-14
CVE-2022-32266 [MEDIUM] CWE-787 CVE-2022-32266: DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe coul DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the SMI handler and lead to corruption of other ACPI fields and adjacent memory fields. DMA attacks on the parameter buffer used by a software SMI handler used by the driver PcdSmmDxe could lead to a TOCTOU attack on the S
nvd
CVE-2022-30773MEDIUMCVSS 6.4≥ 5.4, < 5.4.05.44.23≥ 5.5, < 5.5.05.52.232022-11-14
CVE-2022-30773 [MEDIUM] CWE-367 CVE-2022-30773: DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after para DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). DMA attacks on the parameter buffer used by the IhisiSmm driver could change the contents after parameter values have been checked but before they are used (a TOCTOU attack). T
nvd
CVE-2022-33907MEDIUMCVSS 6.4≥ 5.2, < 5.2.05.27.25≥ 5.3, < 5.3.05.36.25+1 more2022-11-14
CVE-2022-33907 [MEDIUM] CWE-367 CVE-2022-33907: DMA transactions which are targeted at input buffers used for the software SMI handler used by the I DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver could cause SMRAM corruption through a TOCTOU attack... DMA transactions which are targeted at input buffers used for the software SMI handler used by the IdeBusDxe driver could cause SMRAM corruption through a TOCTOU attack. This issu
nvd
CVE-2021-38578CRITICALCVSS 9.8v5.0v5.1+4 more2022-03-03
CVE-2021-38578 [CRITICAL] CWE-124 CVE-2021-38578: Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
nvd
CVE-2021-38575HIGHCVSS 8.1v5.0v5.1+4 more2021-12-01
CVE-2021-38575 [HIGH] CWE-124 CVE-2021-38575: NetworkPkg/IScsiDxe has remotely exploitable buffer overflows. NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
nvd