Database/Firmware, BMC & network fabric

Insyde InsydeH2O (UsbCoreDxe SMM module): Another SMM callout in the USB core driver
Impact
Another SMM callout in the USB core driver - improper input validation lets SMM be redirected into attacker-controlled code outside SMRAM, giving ring -2 execution. Notable mainly because it is the same driver family Insyde has now patched repeatedly (2021 through 2024), which tells an operator something useful: assume the USB stack in your BIOS will need patching again, and build the flash cadence to match rather than treating each one as a one-off.
Who can reach it
Local admin/root on the host OS triggering the vulnerable SMI.
What to do
OEM BIOS update on Insyde kernel 5.4 / 05.47.01, 5.5 / 05.55.01, 5.6 / 05.62.01, 5.7 / 05.71.01 or later. Firmware flash, one reboot per node. Partial config workaround: disable USB legacy/emulation support in BIOS on headless GPU nodes, which shrinks the reachable surface without a flash - but confirm on your platform that it actually unloads the SMM module.
References
Related entries
- GRUB2 (network config file search): grub_net_search_config_file copies a network-controlled variable with strcpyCVE-2025-0624 · GRUB2 (network config file search)High
- Linux kernel (drivers/infiniband/hw/bnxt_re): The NVMe-oF target host panics the moment a client connects.CVE-2025-21885 · Linux kernel (drivers/infiniband/hw/bnxt_re)High
- Dell Enterprise SONiC OS 4.5.0 (SSH cryptographic key): The SSH cryptographic-key weakness recurring in EnterpriseCVE-2025-38741 · Dell Enterprise SONiC OS 4.5.0 (SSH cryptographic key)High
- Fujitsu / Fsas Technologies iRMC S6 BMC (M5-generation servers): A length-boundary bug in BMC authenticationCVE-2025-65002 · Fujitsu / Fsas Technologies iRMC S6 BMC (M5-generation servers)High
- IBM PowerVM partition firmware: malformed network-boot packet yields code execution inside the booting partitionCVE-2026-18821 · IBM PowerVM partition firmware (network boot packet handling)High
- Linux kernel NVMe-oF TCP target (nvmet-tcp, H2C_DATA PDU before CONNECT): Nvmet_tcp_build_pdu_iovec() dereferences cmdCVE-2026-22998 · Linux kernel NVMe-oF TCP target (nvmet-tcp, H2C_DATA PDU before CONNECT)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.