Database/Firmware, BMC & network fabric

InsydeH2O: mishandled PlatformLangCodes UEFI variable overflows a buffer and exhausts firmware resources
Impact
Faulty handling of the PlatformLangCodes UEFI variable causes a buffer overflow that ends in resource exhaustion and firmware failure. The record gives no evidence of code execution, and Insyde's own vector is unusually constrained - physical access, high attack complexity, existing high privileges and user interaction - so the realistic outcome for an operator is a machine that will not complete firmware initialisation, which on a GPU node means an unplanned RMA-shaped outage rather than a security incident. It is listed here because BIOS-level bricking is expensive to recover on dense accelerator hardware and because operators tracking their IBV's advisory list should see it. Published to NVD on 2026-09-03 from Insyde advisory SA-2022026, five years after the fix.
Who can reach it
Physical access to the machine (AV:P) by someone who already holds high privileges and needs a user-interaction step, per Insyde's own CVSS vector. Not reachable by a tenant workload, over the network, or from a normal local account.
What to do
As with all InsydeH2O issues, the fix arrives as an OEM BIOS release, not from Insyde directly: confirm with the board or system vendor whether the platform runs InsydeH2O and which BIOS build carries SA-2022026, then flash it with the node out of service. Given the physical-access-only vector, this is reasonable to fold into the next scheduled firmware maintenance rather than to open a window for on its own. No fixed version number is stated in the record.
References
Related entries
- GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to startCVE-2022-28736 · GRUB2 (chainloader)Medium
- CryptoPro Secure Disk (signed UEFI bootloader): A Microsoft-signed bootloader that can be made to execute arbitraryCVE-2022-34301 · CryptoPro Secure Disk (signed UEFI bootloader)Medium
- New Horizon Datasys (signed UEFI bootloader): Signed bootloader with a built-in mechanism to bypass Secure BootCVE-2022-34302 · New Horizon Datasys (signed UEFI bootloader)Medium
- Eurosoft (UK) Ltd (signed UEFI bootloader): Signed UEFI bootloader containing a shell that executes arbitrary codeCVE-2022-34303 · Eurosoft (UK) Ltd (signed UEFI bootloader)Medium
- Windows Boot Manager (Secure Boot bypass): The bypass the BlackLotus UEFI bootkit used in the wildCVE-2023-24932 · Windows Boot Manager (Secure Boot bypass)Medium
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's IPMI handler allows an authorised attackerCVE-2023-25508 · NVIDIA DGX BMC (AMI-derived management controller)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.