Database/Firmware, BMC & network fabric

Insyde InsydeH2O (FwBlockServiceSmm): Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL never
Impact
Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL never check whether the buffer address they were given points into SMRAM, MMIO or kernel memory. An OS-level attacker therefore gets SMM to write on their behalf - and FwBlockServiceSmm is the firmware-block service, so this sits directly on the path to the SPI flash. Result is a firmware implant that outlives every reimage and quietly breaks the root of trust the fleet's attestation depends on.
Who can reach it
Local admin/root on the host OS issuing a crafted SMM communication request. No physical access required.
What to do
Fixed in InsydeH2O kernels 05.09.11 / 05.17.11 / 05.27.11 / 05.36.11 / 05.44.11 / 05.52.11 - delivered to you only as an OEM BIOS image, months downstream. Firmware flash, one reboot per node, drain the GPUs first. No configuration mitigates it. Enable and verify SPI write protection (BIOS Lock / protected range registers) as a partial hardening measure, but that does not close the SMM write primitive itself.
References
Related entries
- InsydeH2O: HDD password is stored in plaintext in a UEFI variable readable from the OSCVE-2021-38489 · InsydeH2O UEFI firmware (HDD password stored in a UEFI variable)High
- GRUB2 (shim_lock verifier): The shim_lock verifier let non-kernel files through, so an attacker could get unsignedCVE-2022-28735 · GRUB2 (shim_lock verifier)High
- shim (handle_image PE loader): Buffer overflow in shim's own image loaderCVE-2022-28737 · shim (handle_image PE loader)High
- Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use): UsbCoreDxe uses pointers it was handed without establishing theyCVE-2022-29275 · Insyde InsydeH2O (UsbCoreDxe, untrusted pointer use)High
- Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs): SMI functions in the AHCI/SATA driver consume untrusted inputsCVE-2022-29276 · Insyde InsydeH2O (AhciBusDxe, untrusted SMI inputs)High
- Insyde InsydeH2O (NvmExpressDxe, incorrect pointer checks): The NVMe driver's pointer validation is wrong, allowingCVE-2022-29278 · Insyde InsydeH2O (NvmExpressDxe, incorrect pointer checks)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.