CVE-2021-41837: Buffer Overflow
An issue was discovered in AhciBusDxe in the kernel 5.0 through 5.5 in Insyde InsydeH2O. Because of an Untrusted Pointer Dereference that causes SMM memory corruption, an attacker may be able to write fixed or predictable data to SMRAM. Exploiting this issue could lead to escalating privileges to SMM.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-41837?
CVE-2021-41837 is a vulnerability in AhciBusDxe in the Insyde InsydeH2O kernel versions 5.0 through 5.5 that allows an attacker to write fixed or predictable data to SMRAM, potentially escalating privileges.
How does CVE-2021-41837 affect Insyde InsydeH2O?
CVE-2021-41837 affects Insyde InsydeH2O versions 5.0 through 5.5 by causing an Untrusted Pointer Dereference that leads to SMM memory corruption.
What is the severity of CVE-2021-41837?
CVE-2021-41837 has a severity rating of 8.2, which is considered high.
How can I fix CVE-2021-41837?
To fix CVE-2021-41837, it is recommended to update to a version of Insyde InsydeH2O that is not affected by the vulnerability.
Where can I find more information about CVE-2021-41837?
More information about CVE-2021-41837 can be found in the references provided: [Siemens CERT-Portal](https://cert-portal.siemens.com/productcert/pdf/ssa-306654.pdf), [NetApp Advisory](https://security.netapp.com/advisory/ntap-20220222-0003/), [Insyde Security Pledge](https://www.insyde.com/security-pledge).