CVE-2022-35896: Input Validation
An issue SMM memory leak vulnerability in SMM driver (SMRAM was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. An attacker can dump SMRAM contents via the software SMI provided by the FvbServicesRuntimeDxe driver to read the contents of SMRAM, leading to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-35896?
CVE-2022-35896 is an issue SMM memory leak vulnerability in the SMM driver (SMRAM) discovered in Insyde InsydeH2O with kernel 5.0 through 5.5.
How does CVE-2022-35896 impact the software?
CVE-2022-35896 allows an attacker to dump SMRAM contents via the software SMI provided by the FvbServicesRuntimeDxe driver, leading to information disclosure.
What is the severity of CVE-2022-35896?
The severity of CVE-2022-35896 is medium with a CVSS v3 base score of 6.
How can I fix CVE-2022-35896?
To fix CVE-2022-35896, users should update to a version of Insyde InsydeH2O with a kernel version later than 5.5, as provided by the vendor.
Where can I find more information about CVE-2022-35896?
You can find more information about CVE-2022-35896 on the following references: [Reference 1](https://binarly.io/advisories/BRLY-2022-025/index.html), [Reference 2](https://www.insyde.com/security-pledge), [Reference 3](https://www.insyde.com/security-pledge/SA-2022034).