CVE Vulnerabilities

CVE-2022-26074

Incomplete Cleanup

Published: Aug 18, 2022 | Modified: May 05, 2025
CVSS 3.x
4.4
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

Incomplete cleanup in a firmware subsystem for Intel(R) SPS before versions SPS_E3_04.08.04.330.0 and SPS_E3_04.01.04.530.0 may allow a privileged user to potentially enable denial of service via local access.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

Name Vendor Start Version End Version
Server_platform_services_firmware Intel * sps_e3_04.01.04.530.0 (excluding)
Server_platform_services_firmware Intel sps_e3_04.01.04.530.0 (excluding) sps_e3_04.08.04.330.0 (excluding)

Potential Mitigations

References