In the kernel in Insyde InsydeH2O 5.x, certain SMM drivers did not correctly validate the CommBuffer and CommBufferSize parameters, allowing callers to corrupt either the firmware or the OS memory. The fixed versions for this issue in the AhciBusDxe, IdeBusDxe, NvmExpressDxe, SdHostDriverDxe, and SdMmcDeviceDxe drivers are 05.16.25, 05.26.25, 05.35.25, 05.43.25, and 05.51.25 (for Kernel 5.1 through 5.5).
Metrics
Affected Vendors & Products
References
History
Tue, 11 Aug 2026 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 04 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Status: PUBLISHED
Assigner: mitre
Published: 2021-06-16T15:49:34.000Z
Updated: 2026-08-11T12:22:03.345Z
Reserved: 2020-10-20T00:00:00.000Z
Link: CVE-2020-27339
No data.
Status : Modified
Published: 2021-06-16T16:15:07.897
Modified: 2026-08-11T13:17:18.617
Link: CVE-2020-27339
No data.
ReportizFlow