CVE-2024-52879: High severity insyde h2o vulnerability
An issue was discovered in Insyde InsydeH2O kernel 5.2 before version 05.29.50, kernel 5.3 before version 05.38.50, kernel 5.4 before version 05.46.50, kernel 5.5 before version 05.54.50, kernel 5.6 before version 05.61.50, and kernel 5.7 before version 05.70.50. In VariableRuntimeDxe driver, SmmUpdateVariablePropertySmi () is a SMM callback function and it uses StrCmp () to compare variable names. This action may cause a buffer over-read.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-52879?
CVE-2024-52879 has been classified as a high-severity vulnerability.
How do I fix CVE-2024-52879?
To mitigate CVE-2024-52879, you should update InsydeH2O kernel to version 05.29.50 or later, based on your specific kernel version.
Which versions of InsydeH2O are affected by CVE-2024-52879?
CVE-2024-52879 affects InsydeH2O kernels prior to versions 05.29.50, 05.38.50, 05.46.50, 05.54.50, 05.61.50, and 05.70.50.
What type of issue is described in CVE-2024-52879?
CVE-2024-52879 is related to a security flaw in the VariableRuntimeDxe driver within the InsydeH2O kernel.
When was CVE-2024-52879 disclosed?
CVE-2024-52879 was disclosed in 2024, highlighting a critical security risk in specific versions of InsydeH2O.