CVE-2024-49200

An issue was discovered in AcpiS3SaveDxe and ChipsetSvcDxe in Insyde InsydeH2O with kernel 5.2 though 5.7. A potential DXE memory corruption vulnerability has been identified. The root cause is use of a pointer originating from the value of an NVRAM variable as the target of a write operation. This can be leveraged by an attacker to perform arbitrary writes, potentially leading to arbitrary code execution. The issue has been fixed in kernel 5.2, Version 05.29.44; kernel 5.3, Version 05.38.44; kernel 5.4, Version 05.46.44; kernel 5.5, Version 05.54.44; kernel 5.6, Version 05.61.44; and kernel 5.7, Version 05.70.44.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:insyde:kernel:5.2:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.3:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.4:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.5:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.6:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.7:*:*:*:*:*:*:*

History

30 Apr 2025, 16:41

Type Values Removed Values Added
References () https://www.insyde.com/security-pledge/SA-2024015 - () https://www.insyde.com/security-pledge/SA-2024015 - Vendor Advisory
First Time Insyde kernel
Insyde
CPE cpe:2.3:o:insyde:kernel:5.5:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.3:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.7:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.2:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.4:*:*:*:*:*:*:*
cpe:2.3:o:insyde:kernel:5.6:*:*:*:*:*:*:*

16 Apr 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.4
CWE CWE-787

16 Apr 2025, 13:25

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en AcpiS3SaveDxe y ChipsetSvcDxe en Insyde InsydeH2O con las versiones del kernel 5.2 a 5.7. Se identificó una posible vulnerabilidad de corrupción de memoria DXE. La causa principal es el uso de un puntero originado en el valor de una variable NVRAM como destino de una operación de escritura. Un atacante puede aprovechar esto para realizar escrituras arbitrarias, lo que podría provocar la ejecución de código arbitrario. El problema se ha corregido en las versiones del kernel 5.2, 05.29.44; 5.3, 05.38.44; 5.4, 05.46.44; 5.5, 05.54.44; 5.6, 05.61.44; y 5.7, 05.70.44.

15 Apr 2025, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 22:15

Updated : 2025-04-30 16:41


NVD link : CVE-2024-49200

Mitre link : CVE-2024-49200

CVE.ORG link : CVE-2024-49200


JSON object : View

Products Affected

insyde

  • kernel
CWE
CWE-787

Out-of-bounds Write