CVE-2024-52877

An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, callback function SmmCreateVariableLockList () calls CreateVariableLockListInSmm (). In CreateVariableLockListInSmm (), it uses StrSize () to get variable name size and it could lead to a buffer over-read.
Configurations

No configuration.

History

19 May 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-126

16 May 2025, 14:43

Type Values Removed Values Added
Summary
  • (es) Se detectó un problema en Insyde InsydeH2O en las versiones del kernel 5.2 anterior a la 05.29.50, 5.3 anterior a la 05.38.50, 5.4 anterior a la 05.46.50, 5.5 anterior a la 05.54.50, 5.6 anterior a la 05.61.50 y 5.7 anterior a la 05.70.50. En el controlador VariableRuntimeDxe, la función de devolución de llamada SmmCreateVariableLockList() llama a CreateVariableLockListInSmm(). En CreateVariableLockListInSmm(), utiliza StrSize() para obtener el tamaño del nombre de la variable, lo que podría provocar una sobrelectura del búfer.

15 May 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-15 16:15

Updated : 2025-05-19 20:15


NVD link : CVE-2024-52877

Mitre link : CVE-2024-52877

CVE.ORG link : CVE-2024-52877


JSON object : View

Products Affected

No product.

CWE
CWE-126

Buffer Over-read