Vulnerability Description
An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.45 in Insyde InsydeH2O. Code execution can occur because the SMI handler lacks a CommBuffer check.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Insyde | Insydeh2O | >= 5.0, < 05.08.46 |
References
- https://security.netapp.com/advisory/ntap-20220223-0002/Third Party Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
- https://security.netapp.com/advisory/ntap-20220223-0002/Third Party Advisory
- https://www.insyde.com/security-pledgeVendor Advisory
FAQ
What is CVE-2021-41842?
CVE-2021-41842 is a vulnerability with a CVSS score of 9.8 (CRITICAL). An issue was discovered in AtaLegacySmm in the kernel 5.0 before 05.08.46, 5.1 before 05.16.46, 5.2 before 05.26.46, 5.3 before 05.35.46, 5.4 before 05.43.46, and 5.5 before 05.51.45 in Insyde InsydeH...
How severe is CVE-2021-41842?
CVE-2021-41842 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2021-41842?
Check the references section above for vendor advisories and patch information. Affected products include: Insyde Insydeh2O.