Insyde's Security Pledge
Recent Security Advisories

INSYDE-SA-2022005
Product
CVSS Score
Original Date
Last Revised
InsydeH2O
7.5
2022-01-04
2022-02-08
Summary
SdLegacySmm: Software SMI handler does not verify CommBuffer, allowing untrusted external input (CVE-2020-5956).
Vulnerability Details
CVSS Vector: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
This corresponds to CVE-2020-5956. It affects the driver SdLegacySmm. It was discovered by an external researcher. It was fixed in the following versions:
Solution Information
Kernel 5.1: 05.15.11
Kernel 5.2: 05.25.11
Kernel 5.3: 05.34.11
Kernel 5.4: 05.42.11
Kernel 5.5: Unaffected
Acknowledgements
Revision History
Revision #
Date
Description
1
2022-01-04
Initial Release
1.1
2022-02-08
Added CVSS Rating