An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exis…
High CVSS 8.2
Summary
An issue was discovered in AhciBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (the CommBuffer+8 location).
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
- :
- :
- :
- :
Sources
- NVD DATABASE
Original Links
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220216-0004/ Third Party Advisory
- https://www.insyde.com/security-pledge Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf Third Party Advisory
- https://security.netapp.com/advisory/ntap-20220216-0004/ Third Party Advisory
- https://www.insyde.com/security-pledge Vendor Advisory
- https://www.kb.cert.org/vuls/id/796611
- https://cert-portal.siemens.com/productcert/html/ssa-306654.html
Timeline
- nvd_ingest NVD