Skip to main content

Vendor/product archive

insyde / kernel CVEs

Beta · best-effort

33 CVEs tagged to insyde / kernel0 Critical, 19 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2024-52880

Published May 15, 2025

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 0…

CVSS 7.9 · High
Vendor/product tagsBeta · best-effort

CVE-2024-49200

Published Apr 15, 2025

An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25078

Published May 15, 2024

A memory corruption vulnerability in StorageSecurityCommandDxe in Insyde InsydeH2O before kernel 5.2: IB19130163 in 05.29.07, kernel 5.3: IB19130163 in 05.38.07, kernel 5.4: IB191…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47252

Published Apr 26, 2024

An issue was discovered in PnpSmm in Insyde InsydeH2O with kernel 5.0 through 5.6. There is a possible out-of-bounds access in the SMM communication buffer, leading to tampering.…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-46897

Published Apr 22, 2024

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. The CapsuleIFWUSmm driver does not check the return value from a method or function. This can prevent it f…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-28468

Published Aug 3, 2023

An issue was discovered in FvbServicesRuntimeDxe in Insyde InsydeH2O with kernel 5.0 through 5.5. The FvbServicesRuntimeDxe SMM module exposes an SMI handler that allows an attack…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-36337

Published Nov 23, 2022

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. C…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35407

Published Nov 22, 2022

An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. A…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35897

Published Nov 21, 2022

An stack buffer overflow vulnerability leads to arbitrary code execution issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. If the attacker modifies specific UE…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29279

Published Nov 15, 2022

Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHostDriver and SdMmcDevice Use of a untrusted pointer allows tampering with SMRAM and OS memory in SdHost…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29278

Published Nov 15, 2022

Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressDxe driver can allow tampering…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29276

Published Nov 15, 2022

SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was di…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30772

Published Nov 15, 2022

Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSmm driver is passed the address…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30771

Published Nov 15, 2022

Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead to SMRAM corruption when usin…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-30283

Published Nov 15, 2022

In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an att…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29275

Published Nov 15, 2022

In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33986

Published Nov 15, 2022

DMA attacks on the parameter buffer used by the VariableRuntimeDxe software SMI handler could lead to a TOCTOU attack. DMA attacks on the parameter buffer used by the software SMI…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33985

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the NvmExpressDxe software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which a…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33984

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the SdMmcDevice software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33983

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the NvmExpressLegacy software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions whic…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33909

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the HddPassword software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which are…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33908

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the SdHostDriver software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions which ar…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-33906

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the FwBlockServiceSmm software SMI handler could cause SMRAM corruption through a TOCTOU attack. DMA transactions whi…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-33905

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the AhciBusDxe software SMI handler could cause SMRAM corruption (a TOCTOU attack). DMA transactions which are target…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2022-32267

Published Nov 15, 2022

DMA transactions which are targeted at input buffers used for the SmmResourceCheckDxe software SMI handler cause SMRAM corruption (a TOCTOU attack) DMA transactions which are targ…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 33 CVEsPage 1 of 2