CVE-2023-28396
Published Feb 14, 2024Improper access control in firmware for some Intel(R) Thunderbol(TM) Controllers versions before 41 may allow a privileged user to enable denial of service via local access.
Vendor/product archive
2 CVEs tagged to intel / jhl8440 — 0 Critical, 1 High, 1 Medium, 0 Low, 0 Unrated.
Improper access control in firmware for some Intel(R) Thunderbol(TM) Controllers versions before 41 may allow a privileged user to enable denial of service via local access.
In psi_write of psi.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privile…