Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-54545 | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, callback function SmmCreateVariableLockList () calls CreateVariableLockListInSmm (). In CreateVariableLockListInSmm (), it uses StrSize () to get variable name size and it could lead to a buffer over-read. |
Fri, 15 Aug 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Insyde
Insyde insydeh2o |
|
| CPEs | cpe:2.3:a:insyde:insydeh2o:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Insyde
Insyde insydeh2o |
Mon, 19 May 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-126 | |
| Metrics |
cvssV3_1
|
Thu, 15 May 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, callback function SmmCreateVariableLockList () calls CreateVariableLockListInSmm (). In CreateVariableLockListInSmm (), it uses StrSize () to get variable name size and it could lead to a buffer over-read. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-05-19T20:02:26.495Z
Reserved: 2024-11-17T00:00:00.000Z
Link: CVE-2024-52877
Updated: 2025-05-19T20:02:17.972Z
Status : Analyzed
Published: 2025-05-15T16:15:32.770
Modified: 2025-08-15T17:06:05.607
Link: CVE-2024-52877
No data.
OpenCVE Enrichment
No data.
EUVD