Buffer Overflow Vulnerability in Firmware by Insyde Software
CVE-2026-9805

2.7LOW

Key Information:

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-9805?

A buffer overflow vulnerability exists in the SMM IHISI command handler of Insyde Software's firmware. Specifically, the FMTSWriteUseIntelLib function for command 0x32 can read and write data without proper buffer size validation. This lack of validation can lead to potential exploitation, allowing attackers to overwrite memory, which may result in unauthorized access to sensitive data or system instability.

Affected Version(s)

InsydeH2O x86 See in the Solution

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Physical
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.