Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-11151 | An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution. The issue has been fixed in kernel 5.2, Version 05.29.44; kernel 5.3, Version 05.38.44; kernel 5.4, Version 05.46.44; kernel 5.5, Version 05.54.44; kernel 5.6, Version 05.61.44; and kernel 5.7, Version 05.70.44. |
| Link | Providers |
|---|---|
| https://www.insyde.com/security-pledge/SA-2024015 |
|
Wed, 30 Apr 2025 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Insyde
Insyde kernel |
|
| CPEs | cpe:2.3:o:insyde:kernel:5.2:*:*:*:*:*:*:* cpe:2.3:o:insyde:kernel:5.3:*:*:*:*:*:*:* cpe:2.3:o:insyde:kernel:5.4:*:*:*:*:*:*:* cpe:2.3:o:insyde:kernel:5.5:*:*:*:*:*:*:* cpe:2.3:o:insyde:kernel:5.6:*:*:*:*:*:*:* cpe:2.3:o:insyde:kernel:5.7:*:*:*:*:*:*:* |
|
| Vendors & Products |
Insyde
Insyde kernel |
Wed, 16 Apr 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-787 | |
| Metrics |
cvssV3_1
|
Tue, 15 Apr 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution. The issue has been fixed in kernel 5.2, Version 05.29.44; kernel 5.3, Version 05.38.44; kernel 5.4, Version 05.46.44; kernel 5.5, Version 05.54.44; kernel 5.6, Version 05.61.44; and kernel 5.7, Version 05.70.44. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-04-16T18:30:42.300Z
Reserved: 2024-10-13T00:00:00.000Z
Link: CVE-2024-49200
Updated: 2025-04-16T14:47:28.129Z
Status : Analyzed
Published: 2025-04-15T22:15:15.467
Modified: 2025-04-30T16:41:11.493
Link: CVE-2024-49200
No data.
OpenCVE Enrichment
No data.
EUVD