GPU VulnDB

Database/Firmware, BMC & network fabric

Gigabyte UEFI firmware (SMM, NVRAM double pointer dereference): An unvalidated NVRAM variable is dereferenced twice

CVE-2025-7027Firmware, BMC & network fabricVU#746790curated

Impact

An unvalidated NVRAM variable is dereferenced twice inside SMM, letting a local attacker write to SMRAM and gain ring -2 execution. NVRAM variables are writable from the OS on many platforms, which makes this a comparatively short path from host root to firmware-level persistence.

Who can reach it

Local privileged code on the host, able to set the UEFI variable. Any tenant with root on a bare-metal node qualifies.

What to do

Gigabyte BIOS update per board model plus reboot. No config workaround - locking down NVRAM variable writes is not generally available to operators. Bundle with the other three SMM CVEs in the same advisory; they ship in the same image.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.