Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP...
Moderate severity
Unreviewed
Published
May 9, 2023
to the GitHub Advisory Database
•
Updated Apr 11, 2024
Description
Published by the National Vulnerability Database
May 9, 2023
Published to the GitHub Advisory Database
May 9, 2023
Last updated
Apr 11, 2024
Time-of-check Time-of-use (TOCTOU) in the
BIOS2PSP command may allow an attacker with a malicious BIOS to create a race
condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon
an S3 resume event potentially leading to a denial of service.
References