Database/Firmware, BMC & network fabric

Insyde InsydeH2O (VariableRuntimeDxe, SecureBootHandler): The Secure Boot variable handler bounds-checks incoming data
Impact
The Secure Boot variable handler bounds-checks incoming data using length fields that the caller supplies, so an attacker who lies about the sizes gets the handler to read and write outside the buffer. The affected code is the gatekeeper for the Secure Boot key databases (PK/KEK/db/dbx), which means the compromise targets the mechanism that decides what firmware and bootloaders are allowed to run. Highest-scored member of the four-CVE SA-2024016 VariableRuntimeDxe batch.
Who can reach it
Local admin/root on the host OS making crafted SetVariable / SMM variable-service calls.
What to do
OEM BIOS update on Insyde kernel 5.2 / 05.29.50, 5.3 / 05.38.50, 5.4 / 05.46.50, 5.5 / 05.54.50, 5.6 / 05.61.50, 5.7 / 05.70.50 or later. Firmware flash, reboot per node. No config workaround. Patch the whole SA-2024016 set together - CVE-2024-52877, -52878 and -52879 are separate defects in the same driver and a partial fix leaves the driver reachable.
References
Related entries
- Intel Xeon 6 with TDX (protected memory range handling): Improper handling of overlap between protected memory rangesCVE-2025-22889 · Intel Xeon 6 with TDX (protected memory range handling)High
- IBM Power Systems Firmware: BMC/FSP root can read and disrupt host processor state across all partitionsCVE-2026-17063 · IBM Power Systems Firmware (BMC/FSP-to-host interface, processor state)High
- TPM 2.0 reference code: leak lets a privileged local user obtain a CA credential for a falsified TPM keyCVE-2026-6726 · TCG TPM 2.0 reference code (attestation credential handling, TCG VRT0010)High
- Linux kernel RDS RDMA path net/rds/rdma.c - rds_rdma_pages: The page-count arithmetic for an RDS RDMA scatter-gatherCVE-2010-3865 · Linux kernel RDS RDMA path net/rds/rdma.c - rds_rdma_pagesHigh
- Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Integer overflow on theCVE-2010-4649 · Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cqHigh
- Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad): The whole drivers/infinibandCVE-2016-4565 · Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.