Insyde Security Advisory 2022032

Insyde ID Advisory Category Impact of Vulnerability Severity Rating Original Date Last Revised
INSYDE-SA-2022032 Software CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H 8.2 09/21/2022 09/21/2022


SMM memory corruption vulnerability in Software SMI handler in InsydeH2O

Vulnerability Details


This affects the PnpSmm driver of InsydeH2O. This issue was discovered by the Binarly efiXplorer team. This issue is fixed in InsydeH2O, versions:

Kernel 5.0 – Kernel 5.3 (unaffected)
Kernel 5.4 (issue IB19730017 in version 05.44.30)
Kernel 5.5 (issue IB19730017 in version 05.52.30)


Insyde Software would like to thank Binarly for reporting this issue.

Revision History:

Revision Date Description
1.0 09/21/2022 Initial Release
- - -

Return to Insyde's Security Pledge