First published: Tue Nov 15 2022(Updated: )
Incorrect pointer checks within the the FwBlockServiceSmm driver can allow arbitrary RAM modifications During review of the FwBlockServiceSmm driver, certain instances of SpiAccessLib could be tricked into writing 0xff to arbitrary system and SMRAM addresses. Fixed in: INTEL Purley-R: 05.21.51.0048 Whitley: 05.42.23.0066 Cedar Island: 05.42.11.0021 Eagle Stream: 05.44.25.0052 Greenlow/Greenlow-R(skylake/kabylake): Trunk Mehlow/Mehlow-R (CoffeeLake-S): Trunk Tatlow (RKL-S): Trunk Denverton: 05.10.12.0042 Snow Ridge: Trunk Graneville DE: 05.05.15.0038 Grangeville DE NS: 05.27.26.0023 Bakerville: 05.21.51.0026 Idaville: 05.44.27.0030 Whiskey Lake: Trunk Comet Lake-S: Trunk Tiger Lake H/UP3: 05.43.12.0052 Alder Lake: 05.44.23.0047 Gemini Lake: Not Affected Apollo Lake: Not Affected Elkhart Lake: 05.44.30.0018 AMD ROME: trunk MILAN: 05.36.10.0017 GENOA: 05.52.25.0006 Snowy Owl: Trunk R1000: 05.32.50.0018 R2000: 05.44.30.0005 V2000: Trunk V3000: 05.44.30.0007 Ryzen 5000: 05.44.30.0004 Embedded ROME: Trunk Embedded MILAN: Trunk Hygon Hygon #1/#2: 05.36.26.0016 Hygon #3: 05.44.26.0007 https://www.insyde.com/security-pledge/SA-2022060
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AMD Genoa firmware | <05.52.25.0006 | |
AMD Genoa firmware | ||
AMD Hygon 1 firmware | <05.36.26.0016 | |
AMD Hygon 1 firmware | ||
AMD Hygon 2 Firmware | <05.36.26.0016 | |
AMD Hygon 2 Firmware | ||
AMD Hygon 3 | <05.44.26.0007 | |
AMD Hygon 3 | ||
AMD Milan Firmware | <05.36.10.0017 | |
AMD Milan | ||
AMD Milan Firmware | <05.36.26.0016 | |
AMD Milan | ||
AMD ROME firmware | <05.36.10.0017 | |
AMD CPUs | ||
AMD ROME firmware | <05.36.26.0016 | |
AMD CPUs | ||
AMD Ryzen 3 5300G Firmware | <05.44.30.0004 | |
AMD Ryzen 3 5300G | ||
AMD Ryzen 3 5300GE Firmware | <05.44.30.0004 | |
AMD Ryzen 5300GE Firmware | ||
AMD Ryzen 5 5600G Firmware | <05.44.30.0004 | |
AMD Ryzen 5600G Firmware | ||
AMD Ryzen 5 5600GE Firmware | <05.44.30.0004 | |
AMD Ryzen 5 5600GE | ||
AMD Ryzen 5 5600X Firmware | <05.44.30.0004 | |
AMD Ryzen 5 5600X | ||
AMD Ryzen 5 5700G Firmware | <05.44.30.0004 | |
AMD Ryzen 5 5700G | ||
AMD Ryzen 5 5700GE Firmware | <05.44.30.0004 | |
AMD Ryzen 5 5700GE | ||
AMD Ryzen 5800X | <05.44.30.0004 | |
AMD Ryzen 7 5800X | ||
AMD Ryzen 7 5800X3D Firmware | <05.44.30.0004 | |
AMD Ryzen 7 5800X3D | ||
AMD Ryzen 9 5900X Firmware | <05.44.30.0004 | |
AMD Ryzen 9 5900X | ||
AMD Ryzen 9 5950X | <05.44.30.0004 | |
AMD Ryzen 9 5950X | ||
AMD Snowy Owl R1000 | <05.32.50.0018 | |
AMD Snowy Owl R1000 firmware | ||
AMD Snowy Owl R2000 | <05.44.30.0005 | |
AMD Snowy Owl R2000 firmware | ||
AMD Snowy Owl V2000 firmware | <05.44.30.0007 | |
AMD Snowy Owl V2000 firmware | ||
AMD Snowy Owl V3000 | <05.44.30.0007 | |
AMD Snowy Owl V3000 | ||
Intel Alder Lake firmware | <05.44.23.0047 | |
Intel Alder Lake firmware | ||
INTEL Bakerville firmware | <05.21.51.0026 | |
INTEL Bakerville | ||
INTEL Cedar Island | <05.42.11.0021 | |
INTEL Cedar Island | ||
INTEL Idaville firmware | <05.43.12.0052 | |
INTEL Idaville firmware | ||
Intel Comet Lake | <05.43.12.0052 | |
Intel Comet Lake | ||
INTEL Tiger Lake H/UP3 Firmware | <05.43.12.0052 | |
INTEL Tiger Lake H/UP3 | ||
Intel Whiskey Lake firmware | <05.43.12.0052 | |
INTEL Whiskey Lake firmware | ||
INTEL Denverton | <05.10.12.0042 | |
Intel Denverton | ||
Intel Eagle Stream | <05.44.25.0052 | |
Intel Eagle Stream | ||
INTEL Grangeville DE | <05.27.26.0023 | |
Intel Grangeville DE NS firmware | ||
Intel Grangeville DE NS firmware | <05.05.15.0038 | |
INTEL Grangeville De | ||
INTEL Greenlow firmware | <05.10.12.0042 | |
INTEL Greenlow firmware | ||
INTEL Greenlow-R | <05.10.12.0042 | |
INTEL Greenlow-R firmware | ||
INTEL Mehlow | <05.10.12.0042 | |
INTEL Mehlow firmware | ||
INTEL Mehlow-R | <05.10.12.0042 | |
INTEL Mehlow-R firmware | ||
INTEL Tatlow | <05.10.12.0042 | |
INTEL Tatlow firmware | ||
INTEL Purley-R firmware | <05.21.51.0048 | |
INTEL Purley-R firmware | ||
Intel Whitley Firmware | <05.42.23.0066 | |
Intel Whitley Firmware | ||
All of | ||
AMD Genoa firmware | <05.52.25.0006 | |
AMD Genoa firmware | ||
All of | ||
AMD Hygon 1 firmware | <05.36.26.0016 | |
AMD Hygon 1 firmware | ||
All of | ||
AMD Hygon 2 Firmware | <05.36.26.0016 | |
AMD Hygon 2 Firmware | ||
All of | ||
AMD Hygon 3 | <05.44.26.0007 | |
AMD Hygon 3 | ||
All of | ||
AMD Milan Firmware | <05.36.10.0017 | |
AMD Milan | ||
All of | ||
AMD Milan Firmware | <05.36.26.0016 | |
AMD Milan | ||
All of | ||
AMD ROME firmware | <05.36.10.0017 | |
AMD CPUs | ||
All of | ||
AMD ROME firmware | <05.36.26.0016 | |
AMD CPUs | ||
All of | ||
AMD Ryzen 3 5300G Firmware | <05.44.30.0004 | |
AMD Ryzen 3 5300G | ||
All of | ||
AMD Ryzen 3 5300GE Firmware | <05.44.30.0004 | |
AMD Ryzen 5300GE Firmware | ||
All of | ||
AMD Ryzen 5 5600G Firmware | <05.44.30.0004 | |
AMD Ryzen 5600G Firmware | ||
All of | ||
AMD Ryzen 5 5600GE Firmware | <05.44.30.0004 | |
AMD Ryzen 5 5600GE | ||
All of | ||
AMD Ryzen 5 5600X Firmware | <05.44.30.0004 | |
AMD Ryzen 5 5600X | ||
All of | ||
AMD Ryzen 5 5700G Firmware | <05.44.30.0004 | |
AMD Ryzen 5 5700G | ||
All of | ||
AMD Ryzen 5 5700GE Firmware | <05.44.30.0004 | |
AMD Ryzen 5 5700GE | ||
All of | ||
AMD Ryzen 5800X | <05.44.30.0004 | |
AMD Ryzen 7 5800X | ||
All of | ||
AMD Ryzen 7 5800X3D Firmware | <05.44.30.0004 | |
AMD Ryzen 7 5800X3D | ||
All of | ||
AMD Ryzen 9 5900X Firmware | <05.44.30.0004 | |
AMD Ryzen 9 5900X | ||
All of | ||
AMD Ryzen 9 5950X | <05.44.30.0004 | |
AMD Ryzen 9 5950X | ||
All of | ||
AMD Snowy Owl R1000 | <05.32.50.0018 | |
AMD Snowy Owl R1000 firmware | ||
All of | ||
AMD Snowy Owl R2000 | <05.44.30.0005 | |
AMD Snowy Owl R2000 firmware | ||
All of | ||
AMD Snowy Owl V2000 firmware | <05.44.30.0007 | |
AMD Snowy Owl V2000 firmware | ||
All of | ||
AMD Snowy Owl V3000 | <05.44.30.0007 | |
AMD Snowy Owl V3000 | ||
All of | ||
Intel Alder Lake firmware | <05.44.23.0047 | |
Intel Alder Lake firmware | ||
All of | ||
INTEL Bakerville firmware | <05.21.51.0026 | |
INTEL Bakerville | ||
All of | ||
INTEL Cedar Island | <05.42.11.0021 | |
INTEL Cedar Island | ||
All of | ||
INTEL Idaville firmware | <05.43.12.0052 | |
INTEL Idaville firmware | ||
All of | ||
Intel Comet Lake | <05.43.12.0052 | |
Intel Comet Lake | ||
All of | ||
INTEL Tiger Lake H/UP3 Firmware | <05.43.12.0052 | |
INTEL Tiger Lake H/UP3 | ||
All of | ||
Intel Whiskey Lake firmware | <05.43.12.0052 | |
INTEL Whiskey Lake firmware | ||
All of | ||
INTEL Denverton | <05.10.12.0042 | |
INTEL Denverton firmware | ||
All of | ||
Intel Eagle Stream | <05.44.25.0052 | |
Intel Eagle Stream | ||
All of | ||
INTEL Grangeville DE | <05.27.26.0023 | |
Intel Grangeville DE NS firmware | ||
All of | ||
Intel Grangeville DE NS firmware | <05.05.15.0038 | |
INTEL Grangeville De | ||
All of | ||
INTEL Greenlow firmware | <05.10.12.0042 | |
INTEL Greenlow firmware | ||
All of | ||
INTEL Greenlow-R | <05.10.12.0042 | |
INTEL Greenlow-R firmware | ||
All of | ||
INTEL Mehlow | <05.10.12.0042 | |
INTEL Mehlow firmware | ||
All of | ||
INTEL Mehlow-R | <05.10.12.0042 | |
INTEL Mehlow-R firmware | ||
All of | ||
INTEL Tatlow | <05.10.12.0042 | |
INTEL Tatlow firmware | ||
All of | ||
INTEL Purley-R firmware | <05.21.51.0048 | |
INTEL Purley-R firmware | ||
All of | ||
Intel Whitley Firmware | <05.42.23.0066 | |
Intel Whitley Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-29277 is considered high due to its ability to allow arbitrary RAM modifications.
To fix CVE-2022-29277, update to INTEL Purley-R firmware version 05.21.51.0048 or later.
CVE-2022-29277 affects various firmware versions of AMD GENOA, AMD Hygon, AMD Milan, AMD ROME, and others.
The impact of CVE-2022-29277 includes potential unauthorized modifications to system memory, impacting system integrity and security.
Vulnerable versions to CVE-2022-29277 include AMD GENOA firmware versions up to 05.52.25.0006 and certain versions of other AMD and Intel firmware.