CVE-2021-45970: High severity Insyde InsydeH2O vulnerability
An issue was discovered in IdeBusDxe in Insyde InsydeH2O with kernel 5.1 before 05.16.25, 5.2 before 05.26.25, 5.3 before 05.35.25, 5.4 before 05.43.25, and 5.5 before 05.51.25. A vulnerability exists in the SMM (System Management Mode) branch that registers a SWSMI handler that does not sufficiently check or validate the allocated buffer pointer (the status code saved at the CommBuffer+4 location).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-45970?
CVE-2021-45970 is considered a high-severity vulnerability due to its impact on system management mode.
How do I fix CVE-2021-45970?
To fix CVE-2021-45970, you should update the InsydeH2O UEFI BIOS to a version later than the specified vulnerable versions.
Which versions of InsydeH2O are affected by CVE-2021-45970?
CVE-2021-45970 affects InsydeH2O versions prior to 5.16.25, 5.26.25, 5.35.25, 5.43.25, and 5.51.25.
What components are impacted by CVE-2021-45970?
CVE-2021-45970 impacts the ideBusDxe component within the InsydeH2O UEFI BIOS.
What does SMM mean in the context of CVE-2021-45970?
In the context of CVE-2021-45970, SMM stands for System Management Mode, which is a special operating mode for handling system management tasks.