GPU VulnDB

Database/Firmware, BMC & network fabric

Insyde InsydeH2O (FwBlockServiceSmm): Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL never

CVE-2021-33627Firmware, BMC & network fabricINSYDE-SA-2022022VU#796611curated

Impact

Software SMI services reachable through EFI_SMM_COMMUNICATION_PROTOCOL never check whether the buffer address they were given points into SMRAM, MMIO or kernel memory. An OS-level attacker therefore gets SMM to write on their behalf - and FwBlockServiceSmm is the firmware-block service, so this sits directly on the path to the SPI flash. Result is a firmware implant that outlives every reimage and quietly breaks the root of trust the fleet's attestation depends on.

Who can reach it

Local admin/root on the host OS issuing a crafted SMM communication request. No physical access required.

What to do

Fixed in InsydeH2O kernels 05.09.11 / 05.17.11 / 05.27.11 / 05.36.11 / 05.44.11 / 05.52.11 - delivered to you only as an OEM BIOS image, months downstream. Firmware flash, one reboot per node, drain the GPUs first. No configuration mitigates it. Enable and verify SPI write protection (BIOS Lock / protected range registers) as a partial hardening measure, but that does not close the SMM write primitive itself.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.