GPU VulnDB

Database/Firmware, BMC & network fabric

Insyde InsydeH2O (StorageSecurityCommandDxe SMI input buffer, DMA TOCTOU): Highest-scored DMA entry in the 2022 batch

CVE-2022-34325Firmware, BMC & network fabricINSYDE-SA-2022057curated

Impact

Highest-scored DMA entry in the 2022 batch. StorageSecurityCommandDxe issues TCG/Opal security commands to self-encrypting drives, so this driver reaches SED authentication material. An attacker winning the race gets SMRAM corruption plus a position inside the code path that unlocks encrypted drives - which is precisely the control a GPU cloud relies on to claim tenant data is protected at rest between leases.

Who can reach it

An attacker able to drive DMA at host memory while the SMI handler is mid-flight - a malicious PCIe device, a peripheral running attacker-flashed firmware (NIC, GPU, NVMe), or a tenant with a passed-through device that is not behind a correctly configured IOMMU. Notably does NOT require host root, which is what separates this family from the ordinary SMM callout bugs.

What to do

Firmware flash from the server OEM, not from Insyde - the fixed Insyde kernel has to be rebased by Dell/HPE/Lenovo/Supermicro and re-qualified before it reaches you, which for this batch ran months behind Insyde's own release. One reboot per node, so schedule it against a GPU drain. Fixed in the kernel releases named in the advisory (Insyde does not enumerate per-kernel versions for this one). The compensating control that actually works here is the IOMMU, and Insyde says so in the advisory: enable VT-d/AMD-Vi with pre-boot DMA protection so the ACPI runtime buffer the handler reads is not reachable by an untrusted device. That is a BIOS setting, deployable fleet-wide without a flash, and it should be on already on any node that passes devices through to tenants. Patch the batch, not the CVE - Insyde filed one advisory per driver for the same defect, so fixing this one leaves every sibling handler reachable.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.