Database/Firmware, BMC & network fabric

Insyde InsydeH2O (H19Int15CallbackSmm, combined DXE/SMM driver): An unchecked output buffer in a combined DXE/SMM
Impact
An unchecked output buffer in a combined DXE/SMM driver lets an attacker write into SMRAM and reach arbitrary code execution in System Management Mode. The 2025 instalment of the same pattern Binarly and Insyde have been working through since 2021 - a driver that takes an address from the caller and writes to it without confirming the address is outside SMRAM. Ring -2 compromise: survives reinstall, defeats Secure Boot and attestation, invisible from the OS.
Who can reach it
Local admin/root on the host OS issuing the vulnerable SMI with a crafted output buffer address.
What to do
OEM BIOS update carrying Insyde patch IB05690966. Affects Intel Ice Lake and Kaby Lake and AMD Picasso platforms; Insyde scopes the advisory by OEM feature version (HP feature version before 20C1) rather than by kernel version, so map it against your own OEM's BIOS release rather than against an Insyde kernel number. Firmware flash, reboot per node. No config workaround.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.