VYPR
High severity7.0NVD Advisory· Published Feb 15, 2023· Updated Jun 17, 2026

CVE-2022-32475

CVE-2022-32475

Description

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. DMA attacks on the VariableRuntimeDxe shared buffer used by SMM and non-SMM code could cause TOCTOU race-condition issues that could lead to corruption of SMRAM and escalation of privileges. This issue was fixed in the kernel, which also protected chipset and OEM chipset code.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Insyde/InsydeH2Odescription
  • Insyde/InsydeH2Ollm-fuzzy2 versions
    5.0 - 5.5+ 1 more
    • (no CPE)range: 5.0 - 5.5
    • cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:*range: >=5.0,<5.2.05.27.27

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.