Insyde Kernel vulnerabilities
33 known vulnerabilities affecting insyde/kernel.
Total CVEs
33
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH18MEDIUM14
Vulnerabilities
Page 1 of 2
CVE-2024-52880HIGHCVSS 7.9≥ 5.2, < 5.29.50≥ 5.3, < 5.38.50+4 more2025-05-15
CVE-2024-52880 [HIGH] CWE-20 CVE-2024-52880: An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before ve
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SecureBootHandler uses DataSize and VariableNameSize when de
nvd
CVE-2024-49200MEDIUMCVSS 6.4v5.2v5.3+4 more2025-04-15
CVE-2024-49200 [MEDIUM] CWE-787 CVE-2024-49200: An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 thoug
An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrar
nvd
CVE-2024-25078HIGHCVSS 7.4≥ 5.2, < 5.29.07≥ 5.3, < 5.38.07+3 more2024-05-15
CVE-2024-25078 [HIGH] CWE-822 CVE-2024-25078: A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2
A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB19130163 in 05.46.07, kernel 5.5: IB19130163 in 05.54.07, and kernel 5.6: IB19130163 in 05.61.07 could lead to escalating privileges in SMM.
nvd
CVE-2023-47252MEDIUMCVSS 6.3≥ 5.2, < 5.28.45≥ 5.3, < 5.37.45+3 more2024-04-26
CVE-2023-47252 [MEDIUM] CWE-787 CVE-2023-47252: An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possib
An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering. The PNP-related SMI sub-functions do not verify data size before getting it from the communication buffer, which could lead to possible circumstances where the data immedia
nvd
CVE-2022-46897MEDIUMCVSS 5.3≥ 5.0, ≤ 5.52024-04-22
CVE-2022-46897 [MEDIUM] CWE-252 CVE-2022-46897: An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The CapsuleIFWUSmm driver d
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The CapsuleIFWUSmm driver does not check the return value from a method or function. This can prevent it from detecting unexpected states and conditions.
nvd
CVE-2023-28468MEDIUMCVSS 6.5≥ 5.0, ≤ 5.52023-08-03
CVE-2023-28468 [MEDIUM] CWE-863 CVE-2023-28468: An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. Th
An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attacker to interact with the SPI flash at run-time from the OS.
nvd
CVE-2022-36337HIGHCVSS 8.2≥ 5.0, ≤ 5.52022-11-23
CVE-2022-36337 [HIGH] CWE-787 CVE-2022-36337: An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vul
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Control of a UEFI variable under the OS can cause this overflow when read by BIOS code.
nvd
CVE-2022-35407HIGHCVSS 7.8≥ 5.0, ≤ 5.52022-11-22
CVE-2022-35407 [HIGH] CWE-787 CVE-2022-35407: An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow lea
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An attacker can change the values of certain UEFI variables. If the size of the second variable exceeds the size of the first, then the buffer will be overwritten. This issue
nvd
CVE-2022-35897MEDIUMCVSS 6.8≥ 5.0, ≤ 5.52022-11-21
CVE-2022-35897 [MEDIUM] CWE-787 CVE-2022-35897: An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Ins
An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. If the attacker modifies specific UEFI variables, it can cause a stack overflow, leading to arbitrary code execution. The specific variables are normally locked (read-only) at the OS level and therefore an at
nvd
CVE-2022-29276HIGHCVSS 8.2≥ 5.0, < 5.0.05.09.18≥ 5.1, < 5.1.05.17.18+4 more2022-11-15
CVE-2022-29276 [HIGH] CWE-787 CVE-2022-29276: SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in Ah
SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was discovered by Insyde during security review. It was fixed in: Kernel 5.0: version 05.09.18 Kernel 5.1: version 05.17.18 Kernel 5.2: version 05.27.18 Kernel 5.3: version 05.36.1
nvd
CVE-2022-33909HIGHCVSS 7.0≥ 5.2, < 5.2.05.27.23≥ 5.3, < 5.3.05.36.23+2 more2022-11-15
CVE-2022-33909 [HIGH] CWE-367 CVE-2022-33909: DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler c
DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the HddPassword driver could cause SMRAM corruption through a TOCTOU attack..This issue was discovered by
nvd
CVE-2022-29278HIGHCVSS 8.2≥ 5.1, < 5.1.05.17.23≥ 5.2, < 5.2.05.27.23+3 more2022-11-15
CVE-2022-29278 [HIGH] CWE-754 CVE-2022-29278: Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memor
Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory. This issue was discovered by Insyde during security review. Fixed in: Kernel 5.1: Version 05.17.23 Kernel 5.2: Version 05.27.23 Kernel 5.3: Version
nvd
CVE-2022-33984HIGHCVSS 7.0≥ 5.2, < 5.2.05.27.25≥ 5.3, < 5.3.05.36.25+2 more2022-11-15
CVE-2022-33984 [HIGH] CWE-367 CVE-2022-33984: DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler c
DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the SdMmcDevice driver could cause SMRAM corruption through a TOCTOU attack. This issue was discovered by
nvd
CVE-2022-30283HIGHCVSS 7.5≥ 5.0, < 5.0.05.09.21≥ 5.1, < 5.1.05.17.21+4 more2022-11-15
CVE-2022-30283 [HIGH] CWE-367 CVE-2022-30283: In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB tra
In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an attacker to cause SMRAM corruption and escalation of privileges The UsbCoreDxe module creates a working buffer for USB transactions outside of SMRAM. The code which uses can be
nvd
CVE-2022-30771HIGHCVSS 8.2≥ 5.1, < 5.1.05.17.25≥ 5.2, < 5.2.05.27.25+3 more2022-11-15
CVE-2022-30771 [HIGH] CWE-787 CVE-2022-30771: Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI funct
Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions. This issue was discovered by Insyde engineering during a security review. Fixed in: Kernel 5.1: Version 05.17.25 Kernel 5.2: Version 05.27.25
nvd
CVE-2022-29279HIGHCVSS 8.2≥ 5.0, < 5.0.05.09.17≥ 5.1, < 5.1.05.17.17+4 more2022-11-15
CVE-2022-29279 [HIGH] CWE-119 CVE-2022-29279: Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice
Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice. This issue was discovered by Insyde during security review. It was fixed in: Kernel 5.0: version 05.09.17 Kernel 5.1: version 05.17.17 Kernel 5.2: ver
nvd
CVE-2022-33983HIGHCVSS 7.0≥ 5.2, < 5.2.05.27.25≥ 5.3, < 5.3.05.36.25+2 more2022-11-15
CVE-2022-33983 [HIGH] CWE-367 CVE-2022-33983: DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI hand
DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are targeted at input buffers used for the software SMI handler used by the NvmExpressLegacy driver could cause SMRAM corruption through a TOCTOU attack. This issue was dis
nvd
CVE-2022-29275HIGHCVSS 8.2≥ 5.0, ≤ 5.0.05.09.21≥ 5.1, < 5.1.05.17.21+4 more2022-11-15
CVE-2022-29275 [HIGH] CWE-119 CVE-2022-29275: In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers coul
In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This issue was discovered by Insyde during security review. It was fixed in: Kernel 5.0: version 05.09.21 Kernel 5.1: version 05.17.21 Kernel 5.2: version 05.27.21 Kernel 5.3: ver
nvd
CVE-2022-30772HIGHCVSS 8.2≥ 5.0, < 5.0.05.09.41≥ 5.1, < 5.1.05.17.43+4 more2022-11-15
CVE-2022-30772 [HIGH] CWE-787 CVE-2022-30772: Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRA
Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSmm driver is passed the address and size of data to write into the SMBIOS table, but manipulation of the address could be used by malware to overwrite SMRAM or OS kernel memory. This issue was discovered b
nvd
CVE-2022-33905HIGHCVSS 7.0≥ 5.2, < 5.2.05.27.23≥ 5.3, < 5.3.05.36.23+2 more2022-11-15
CVE-2022-33905 [HIGH] CWE-367 CVE-2022-33905: DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler co
DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corruption (a TOCTOU attack). DMA transactions which are targeted at input buffers used for the software SMI handler used by the AhciBusDxe driver could cause SMRAM corruption through a TOCTOU attack. This issue was discovered by Insyde
nvd
1 / 2Next →