In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).
Project Subscriptions
| Vendors | Products |
|---|---|
|
Insyde
Subscribe
|
Insydeh2o
Subscribe
|
|
Siemens
Subscribe
|
Ruggedcom Apr1808
Subscribe
Ruggedcom Apr1808 Firmware
Subscribe
Simatic Field Pg M5
Subscribe
Simatic Field Pg M5 Firmware
Subscribe
Simatic Field Pg M6
Subscribe
Simatic Field Pg M6 Firmware
Subscribe
Simatic Ipc127e
Subscribe
Simatic Ipc127e Firmware
Subscribe
Simatic Ipc227g
Subscribe
Simatic Ipc227g Firmware
Subscribe
Simatic Ipc277g
Subscribe
Simatic Ipc277g Firmware
Subscribe
Simatic Ipc327g
Subscribe
Simatic Ipc327g Firmware
Subscribe
Simatic Ipc377g
Subscribe
Simatic Ipc377g Firmware
Subscribe
Simatic Ipc427e
Subscribe
Simatic Ipc427e Firmware
Subscribe
Simatic Ipc477e
Subscribe
Simatic Ipc477e Firmware
Subscribe
Simatic Ipc477e Pro
Subscribe
Simatic Ipc477e Pro Firmware
Subscribe
Simatic Ipc627e
Subscribe
Simatic Ipc627e Firmware
Subscribe
Simatic Ipc647e
Subscribe
Simatic Ipc647e Firmware
Subscribe
Simatic Ipc677e
Subscribe
Simatic Ipc677e Firmware
Subscribe
Simatic Ipc847e
Subscribe
Simatic Ipc847e Firmware
Subscribe
Simatic Itp1000
Subscribe
Simatic Itp1000 Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-19852 | In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-11-04T19:12:22.115Z
Reserved: 2020-10-20T00:00:00.000Z
Link: CVE-2020-27339
No data.
Status : Modified
Published: 2021-06-16T16:15:07.897
Modified: 2025-11-04T20:15:58.603
Link: CVE-2020-27339
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD