Database/Firmware, BMC & network fabric

Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver): An unchecked output buffer in a combined DXE/SMM
Impact
An unchecked output buffer in a combined DXE/SMM driver lets an attacker write into SMRAM and reach arbitrary code execution in System Management Mode. The 2025 instalment of the same pattern Binarly and Insyde have been working through since 2021 - a driver that takes an address from the caller and writes to it without confirming the address is outside SMRAM. Ring -2 compromise: survives reinstall, defeats Secure Boot and attestation, invisible from the OS.
Who can reach it
Local admin/root on the host OS issuing the vulnerable SMI with a crafted output buffer address.
What to do
OEM BIOS update carrying Insyde patch IB05690966. Affects Intel Ice Lake and Kaby Lake and AMD Picasso platforms; Insyde scopes the advisory by OEM feature version (HP feature version before 20C1) rather than by kernel version, so map it against your own OEM's BIOS release rather than against an Insyde kernel number. Firmware flash, reboot per node. No config workaround.
References
Related entries
- Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12: ImproperCVE-2025-25210 · Intel Server Firmware Update Utility (SysFwUpdt) and Server Configuration Utility before version 16.0.12High
- AMI AptioV UEFI BIOS (SMM): A write-what-where primitive plus an information leak in System Management ModeCVE-2025-33045 · AMI AptioV UEFI BIOS (SMM)High
- Broadcom NetXtreme-E network adapter firmware: A high-severity flaw in the firmware of Broadcom NetXtreme-E adaptersCVE-2025-56547 · Broadcom NetXtreme-E network adapter firmwareHigh
- IBM Power Systems Firmware: BMC/FSP-to-host interface allows arbitrary code execution on the host systemCVE-2026-16930 · IBM Power Systems Firmware (BMC/FSP-to-host interface)High
- IBM Power Systems Firmware: BMC/FSP can read and write arbitrary host system memoryCVE-2026-16933 · IBM Power Systems Firmware (BMC/FSP-to-host memory interface)High
- IBM Power Systems Firmware: crafted configuration data from the BMC/FSP compromises the host boot stageCVE-2026-17093 · IBM Power Systems Firmware (host firmware configuration parsing)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.