Database/Firmware, BMC & network fabric

Insyde InsydeH2O (PnpSmm function 0x52, SMBIOS write address manipulation): PnpSmm function 0x52 takes an address
Impact
PnpSmm function 0x52 takes an address and a size for data to write into the SMBIOS table and does not constrain where that address points. Malware supplies its own address and overwrites SMRAM or OS kernel memory - an arbitrary write primitive handed over by a documented firmware function, no race and no exotic hardware needed. The cleanest escalation in the batch.
Who can reach it
Local admin/root on the host OS invoking the vulnerable software SMI with attacker-chosen pointers. On bare-metal GPU rental this is exactly the privilege the tenant already holds on their leased node.
What to do
Firmware flash from the server OEM, not from Insyde - the fixed Insyde kernel has to be rebased by Dell/HPE/Lenovo/Supermicro and re-qualified before it reaches you, which for this batch ran months behind Insyde's own release. One reboot per node, so schedule it against a GPU drain. Fixed in kernel 5.0 / 05.09.41, 5.1 / 05.17.43, 5.2 / 05.27.30, 5.3 / 05.36.30, 5.4 / 05.44.30, 5.5 / 05.52.30. The compensating control that actually works here is the IOMMU, and Insyde says so in the advisory: enable VT-d/AMD-Vi with pre-boot DMA protection so the ACPI runtime buffer the handler reads is not reachable by an untrusted device. That is a BIOS setting, deployable fleet-wide without a flash, and it should be on already on any node that passes devices through to tenants. Patch the batch, not the CVE - Insyde filed one advisory per driver for the same defect, so fixing this one leaves every sibling handler reachable.
References
Related entries
- Insyde InsydeH2O (UsbLegacyControlSmm): A classic SMM callout: code running inside SMM calls out to a function pointerCVE-2022-35408 · Insyde InsydeH2O (UsbLegacyControlSmm)High
- Insyde InsydeH2O (MebxConfiguration DXE driver): A UEFI variable that the OS can write is read back by BIOS codeCVE-2022-36337 · Insyde InsydeH2O (MebxConfiguration DXE driver)High
- AMI MegaRAC SPx (Dynamic Redfish Extension): Code injection executed via the Dynamic Redfish Extension interfaceCVE-2023-34330 · AMI MegaRAC SPx (Dynamic Redfish Extension)High
- Signed third-party UEFI application (Howyar Reloader and OEM rebrands): A Microsoft-signed UEFI recovery applicationCVE-2024-7344 · Signed third-party UEFI application (Howyar Reloader and OEM rebrands)High
- Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver): An unchecked output buffer in a combined DXE/SMMCVE-2025-10451 · Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver)High
- Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12: ImproperCVE-2025-25210 · Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.