First published: Wed Sep 21 2022(Updated: )
An issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An attacker can dump SMRAM contents via the software SMI provided by the FvbServicesRuntimeDxe driver to read the contents of SMRAM, leading to information disclosure.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Insyde InsydeH2O | >=5.0<=5.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35896 is an issue SMM memory leak vulnerability in the SMM driver (SMRAM) discovered in Insyde InsydeH2O with kernel 5.0 through 5.5.
CVE-2022-35896 allows an attacker to dump SMRAM contents via the software SMI provided by the FvbServicesRuntimeDxe driver, leading to information disclosure.
The severity of CVE-2022-35896 is medium with a CVSS v3 base score of 6.
To fix CVE-2022-35896, users should update to a version of Insyde InsydeH2O with a kernel version later than 5.5, as provided by the vendor.
You can find more information about CVE-2022-35896 on the following references: [Reference 1](https://binarly.io/advisories/BRLY-2022-025/index.html), [Reference 2](https://www.insyde.com/security-pledge), [Reference 3](https://www.insyde.com/security-pledge/SA-2022034).