Loading HuntDB...

GHSA-62pp-fmpv-gcf4

GitHub Security Advisory

⚠ Unreviewed HIGH Has CVE

Advisory Details

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of Trust for BIOS update, to bypass SMM isolation potentially resulting in arbitrary code execution at the SMM level.

Related CVEs

Key Information

GHSA ID
GHSA-62pp-fmpv-gcf4
Published
September 6, 2025 6:30 PM
Last Modified
September 6, 2025 6:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 9, 2025 6:37 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.