Insyde's Security Pledge

Recent Security Advisories

INSYDE-SA-2022004

Product

CVSS Score

Original Date

Last Revised

InsydeH2O

8.2

2022-01-04

2022-02-08

Summary

AtaLegacySmm: SMI handler does not check CommBuffer leading to possible arbitrary code execution.

Vulnerability Details

CVSS Vector: AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

CVE-2021-41842

This corresponds to CVE-2021-41842 It affects the driver AtaLegacySmm. This issue was discovered by an external researcher. It was fixed in the following versions:

Solution Information

Kernel 5.0: 05.08.46
Kernel 5.1: 05.16.46
Kernel 5.2: 05.26.46
Kernel 5.3: 05.35.46
Kernel 5.4: 05.43.46
Kernel 5.5: 05.51.45.

Acknowledgements

Revision History

Revision #

Date

Description

1

2022-01-04

Initial Release

1.1

2022-02-08

Added CVSS Rating