CVE Vulnerabilities

CVE-2022-26074

Incomplete Cleanup

Published: Aug 18, 2022 | Modified: Oct 07, 2022
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incomplete cleanup in a firmware subsystem for Intel(R) SPS before versions SPS_E3_04.08.04.330.0 and SPS_E3_04.01.04.530.0 may allow a privileged user to potentially enable denial of service via local access.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Server_platform_services_firmware Intel * sps_e3_04.01.04.530.0 (excluding)
Server_platform_services_firmware Intel sps_e3_04.01.04.530.0 (excluding) sps_e3_04.08.04.330.0 (excluding)

Potential Mitigations

References