An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overflow when read by BIOS code.
References
| Link | Resource |
|---|---|
| https://www.insyde.com/security-pledge | Vendor Advisory |
| https://www.insyde.com/security-pledge/SA-2022039 | Vendor Advisory |
| https://www.insyde.com/security-pledge | Vendor Advisory |
| https://www.insyde.com/security-pledge/SA-2022039 | Vendor Advisory |
Configurations
History
25 Apr 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-121 |
21 Nov 2024, 07:12
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://www.insyde.com/security-pledge - Vendor Advisory | |
| References | () https://www.insyde.com/security-pledge/SA-2022039 - Vendor Advisory |
30 Nov 2022, 15:27
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:o:insyde:kernel:*:*:*:*:*:*:*:* | |
| CWE | CWE-787 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.2 |
| References | (MISC) https://www.insyde.com/security-pledge/SA-2022039 - Vendor Advisory | |
| References | (MISC) https://www.insyde.com/security-pledge - Vendor Advisory |
23 Nov 2022, 13:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2022-11-23 03:15
Updated : 2025-04-25 21:15
NVD link : CVE-2022-36337
Mitre link : CVE-2022-36337
CVE.ORG link : CVE-2022-36337
JSON object : View
Products Affected
insyde
- kernel
