CVE-2020-27339: Input Validation
In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
InsydeH2O 5.x kernel SMM drivers: AhciBusDxeto a version that resolves this vulnerability.Fixed in 05.16.25 - Upgrade
Upgrade
InsydeH2O 5.x kernel SMM drivers: IdeBusDxeto a version that resolves this vulnerability.Fixed in 05.26.25 - Upgrade
Upgrade
InsydeH2O 5.x kernel SMM drivers: NvmExpressDxeto a version that resolves this vulnerability.Fixed in 05.35.25 - Upgrade
Upgrade
InsydeH2O 5.x kernel SMM drivers: SdHostDriverDxeto a version that resolves this vulnerability.Fixed in 05.43.25 - Upgrade
Upgrade
InsydeH2O 5.x kernel SMM drivers: SdMmcDeviceDxeto a version that resolves this vulnerability.Fixed in 05.51.25
Event History
Frequently Asked Questions
What is the severity of CVE-2020-27339?
The severity of CVE-2020-27339 is high.
What is the affected software for CVE-2020-27339?
The affected software for CVE-2020-27339 is Insyde InsydeH2O 5.x.
How does CVE-2020-27339 impact Insyde InsydeH2O 5.x?
CVE-2020-27339 can allow callers to corrupt either the firmware or the OS memory.
Are there any fixed versions for CVE-2020-27339?
Yes, the fixed versions for CVE-2020-27339 are available for the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and Sd.
Where can I find more information about CVE-2020-27339?
You can find more information about CVE-2020-27339 in the references provided: [Reference 1](https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf), [Reference 2](https://security.netapp.com/advisory/ntap-20220216-0005/), [Reference 3](https://www.insyde.com/security-pledge/SA-2021001).