PT-2022-7532 · Linux+3 · Linux Kernel+3

Aditya Garg

·

Published

2022-01-23

·

Updated

2024-09-25

·

CVE-2022-48769

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description The issue is related to the Linux kernel's use of EFIv2 runtime services on Apple x86 machines. A call to QueryVariableInfo(), which was added in EFI v2.00, can cause crashes in the firmware when using variable services at runtime. This is because Apple machines have only recently upgraded from EFI v1.10 to EFI v2.40 firmware, and Linux support for the newly introduced runtime services was added in 2011. QueryVariableInfo() is used to safely set variables, preventing machines with buggy firmwares from corrupting their NVRAMs when they run out of space.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07040
CVE-2022-48769
OPENSUSE-SU-2024_2372-1
OPENSUSE-SU-2024_2394-1
SUSE-SU-2024:2372-1
SUSE-SU-2024:2394-1
SUSE-SU-2024:2902-1
SUSE-SU-2024:2929-1
SUSE-SU-2024:2939-1
SUSE-SU-2024:3189-1
SUSE-SU-2024:3251-1
SUSE-SU-2024:3252-1

Affected Products

Astra Linux
Linux Kernel
Red Os
Suse