GPU VulnDB

Database/Firmware, BMC & network fabric

Insyde InsydeH2O (VariableRuntimeDxe, SecureBootHandler): The Secure Boot variable handler bounds-checks incoming data

CVE-2024-52880Firmware, BMC & network fabricINSYDE-SA-2024016curated

Impact

The Secure Boot variable handler bounds-checks incoming data using length fields that the caller supplies, so an attacker who lies about the sizes gets the handler to read and write outside the buffer. The affected code is the gatekeeper for the Secure Boot key databases (PK/KEK/db/dbx), which means the compromise targets the mechanism that decides what firmware and bootloaders are allowed to run. Highest-scored member of the four-CVE SA-2024016 VariableRuntimeDxe batch.

Who can reach it

Local admin/root on the host OS making crafted SetVariable / SMM variable-service calls.

What to do

OEM BIOS update on Insyde kernel 5.2 / 05.29.50, 5.3 / 05.38.50, 5.4 / 05.46.50, 5.5 / 05.54.50, 5.6 / 05.61.50, 5.7 / 05.70.50 or later. Firmware flash, reboot per node. No config workaround. Patch the whole SA-2024016 set together - CVE-2024-52877, -52878 and -52879 are separate defects in the same driver and a partial fix leaves the driver reachable.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.