CVE-2022-29276: High severity insyde kernel vulnerability
SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was discovered by Insyde during security review. It was fixed in: Kernel 5.0: version 05.09.18 Kernel 5.1: version 05.17.18 Kernel 5.2: version 05.27.18 Kernel 5.3: version 05.36.18 Kernel 5.4: version 05.44.18 Kernel 5.5: version 05.52.18 https://www.insyde.com/security-pledge/SA-2022059
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29276?
CVE-2022-29276 is a vulnerability in the SMI functions of AhciBusDxe that allows for the corruption of SMRAM due to untrusted inputs.
Who discovered CVE-2022-29276?
CVE-2022-29276 was discovered by Insyde during a security review.
What is the severity of CVE-2022-29276?
CVE-2022-29276 has a severity rating of 8.2 (high).
How can I check if my version of Insyde Kernel is affected by CVE-2022-29276?
You can check if your version of Insyde Kernel is affected by CVE-2022-29276 by comparing the version range mentioned in the CPE (Common Platform Enumeration) with your installed version.
How do I fix CVE-2022-29276?
To fix CVE-2022-29276, you should update your Insyde Kernel to version 05.09.18 or later for Kernel 5.0, version 05.17.18 or later for Kernel 5.1, or a later fixed version for other affected kernel versions.