Back

Security Bulletin, September 2026

CVE-2023-20572, CVE-2025-31936, CVE-2025-31938, CVE-2021-46747, CVE-2024-36343, CVE-2025-10263, CVE-2025-31356, CVE-2025-35973, CVE-2025-54509, CVE-2025-11187, CVE-2026-20705, CVE-2026-20707, CVE-2026-20708, CVE-2026-20712, CVE-2026-20713, CVE-2026-20715, CVE-2026-20734, CVE-2026-20760, CVE-2026-20775, CVE-2026-20885, CVE-2026-20898, CVE-2026-20901, CVE-2026-20917, CVE-2026-6726, CVE-2026-6727, CVE-2023-31316, CVE-2024-36315, CVE-2025-15467, CVE-2025-61971, CVE-2025-61972, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69421, CVE-2026-0438, CVE-2026-20716, CVE-2026-22795, CVE-2026-22796
Oct 07, 2026

Giga Computing Technology Co., Ltd. acknowledges the security vulnerabilities affecting GIGABYTE′s enterprise products. The platforms with released BIOS updates are listed below.

 

CVE-2023-20572

AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors

CVE-2025-31936

Intel® Xeon® 6 Processors

CVE-2025-31938

Intel® Xeon® 6 Processors

CVE-2021-46747

AMD EPYC™ 9005 Server Processors
AMD EPYC™ 9004 Server Processors
AMD EPYC™ 8004 Server Processors
AMD EPYC™ 7003 Series Processors
AMD Instinct™ MI300A APU

CVE-2024-36343

AMD EPYC™ 9005 Server Processors
AMD EPYC™ 9004 Server Processors
AMD EPYC™ 8004 Server Processors
AMD EPYC™ 7003 Series Processors
AMD Instinct™ MI300A APU

AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors

CVE-2025-10263

Ampere® Altra®/Altra® Max Processors

CVE-2025-31356

Intel® Xeon® 6 Processors
5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

CVE-2025-35973

Intel® Xeon® 6 Processors

CVE-2025-54509

AMD EPYC™ 9005 Server Processors
AMD EPYC™ 9004 Server Processors
AMD EPYC™ 8004 Server Processors

CVE-2025-11187

AMD EPYC™ 9005 Server Processors
AMD EPYC™ 9004 Server Processors
AMD EPYC™ 7003 Series Processors

AMD Instinct™ MI300A APU
AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors

AmpereOne X Processors

Ampere® Altra®/Altra® Max Processors
Intel® Xeon® 6 Processors
5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

3rd Gen Intel® Xeon® Scalable Processors
Intel® Xeon® E-2400 Series Processors
Intel® Xeon® E-2300 Series Processors
Intel® Xeon® W-3500/2500/3400/2400 Processors

NVIDIA Grace™ CPU

CVE-2026-20705

Intel® Xeon® 6 Processors
5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

Intel® Xeon® E-2300 Series Processors

CVE-2026-20707

3rd Gen Intel® Xeon® Scalable Processors

Intel® Xeon® E-2300 Series Processors

CVE-2026-20708

5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

Intel® Xeon® E-2300 Series Processors

Intel® Xeon® W-3500/2500/3400/2400 Processors

14th/13th/12th Gen Intel® Core™ Processors

CVE-2026-20712

Intel® Xeon® 6 Processors

5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

3rd Gen Intel® Xeon® Scalable Processors

Intel® Xeon® E-2300 Series Processors

Intel® Xeon® W-3500/2500/3400/2400 Processors

CVE-2026-20713

Intel® Xeon® 6 Processors

5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

Intel® Xeon® E-2300 Series Processors

Intel® Xeon® W-3500/2500/3400/2400 Processors

CVE-2026-20715

5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

Intel® Xeon® E-2300 Series Processors

Intel® Xeon® W-3500/2500/3400/2400 Processors

14th/13th/12th Gen Intel® Core™ Processors

CVE-2026-20734

5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

Intel® Xeon® E-2300 Series Processors

Intel® Xeon® W-3500/2500/3400/2400 Processors

14th/13th/12th Gen Intel® Core™ Processors

CVE-2026-20760

Intel® Xeon® E-2300 Series Processors

CVE-2026-20775

Intel® Xeon® 6 Processors

Intel® Xeon® E-2300 Series Processors

CVE-2026-20885

Intel® Xeon® 6 Processors

5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

Intel® Xeon® E-2300 Series Processors

CVE-2026-20898

Intel® Xeon® 6 Processors

5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

Intel® Xeon® E-2300 Series Processors

CVE-2026-20901

5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

Intel® Xeon® E-2300 Series Processors

CVE-2026-20917

Intel® Xeon® E-2300 Series Processors

CVE-2026-6726, CVE-2026-6727

AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors

CVE-2023-31316

AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors

CVE-2024-36315

AMD EPYC™ 9005 Server Processors
AMD EPYC™ 9004 Server Processors
AMD Instinct™ MI300A APU

AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors

CVE-2025-15467, CVE-2025-68160, CVE-2025-69418, CVE-2025-69419, CVE-2025-69421, CVE-2026-22795, CVE-2026-22796

AMD EPYC™ 9005 Server Processors
AMD EPYC™ 9004 Server Processors
AMD EPYC™ 7003 Series Processors

AMD Instinct™ MI300A APU
AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors

AmpereOne X Processors

Ampere® Altra®/Altra® Max Processors
Intel® Xeon® 6 Processors
5th/4th Gen Intel® Xeon® Scalable Processors & Intel® Xeon® CPU Max Series

3rd Gen Intel® Xeon® Scalable Processors
Intel® Xeon® E-2400 Series Processors
Intel® Xeon® E-2300 Series Processors
Intel® Xeon® W-3500/2500/3400/2400 Processors

NVIDIA Grace™ CPU

CVE-2025-61971

AMD EPYC™ 9005 Server Processors
AMD EPYC™ 9004 Server Processors
AMD EPYC™ 8004 Server Processors
AMD EPYC™ 7003 Series Processors

CVE-2025-61972

AMD EPYC™ 9005 Server Processors
AMD EPYC™ 9004 Server Processors
AMD EPYC™ 8004 Server Processors

CVE-2026-0438

AMD EPYC™ 4005/4004 & Ryzen™ 9000/7000 Series Processors

CVE-2026-20716

Intel® Xeon® 6 Processors

[Note] Platforms using Insyde BIOS do not follow the BIOS release schedule for AMD EPYC 9005/9004 server processors. Please contact our sales team for further information on the BIOS release plan.

 

The vulnerabilities are listed below. Updated BIOS versions to address the threats will be available on all affected product pages.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2023-20572

Severity Rating: Medium

Description: An observable timing discrepancy in the ASP could allow a privileged attacker to perform a brute-force attack against the hash message authentication code, allowing the input of an arbitrary message, potentially leading to a loss of data integrity.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-31936

Severity Rating: High

Description: Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-31938

Severity Rating: Medium

Description: Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2021-46747

Severity Rating: High

Description: Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures leading to a potential escalation of privileges.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2024-36343

Severity Rating: Medium

Description: Improper input validation in the System Management Mode (SMM) communications buffer could allow a privileged attacker to perform an out of bounds read or write to a limited section of the Top of Memory Segment (TSEG) memory region, potentially resulting in loss of confidentiality or integrity.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-10263

Severity Rating: Critical

Description: Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C, Cortex-A77, Cortex-A76 & A76A may allow writes to resources owned by a higher exception level.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-31356

Severity Rating: Medium

Description: Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without any user interaction. The potential vulnerability may impact the confidentiality (high), integrity (low) and no effect on availability. Subsequent system impacts include reduced confidentiality (low), integrity (low), and no effect on availability.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-35973

Severity Rating: Medium

Description: Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and require no user interaction. The potential vulnerability may impact the confidentiality (low), integrity (low) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-54509

Severity Rating: Medium

Description: Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure Processor (ASP), potentially resulting in loss of integrity.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-11187

Severity Rating: Medium

Description: PBMAC1 parameters in PKCS#12 files are missing validation which can trigger a stack-based buffer overflow, invalid pointer or NULL pointer dereference during MAC verification. The stack buffer overflow or NULL pointer dereference may cause a crash leading to Denial of Service for an application that parses untrusted PKCS#12 files. The buffer overflow may also potentially enable code execution depending on platform mitigations.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20705

Severity Rating: Medium

Description: Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20707

Severity Rating: Medium

Description: Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20708

Severity Rating: Medium

Description: Insertion of sensitive information into log file in the subsystem for the Intel(R) AMT and Intel(R) Standard Manageability may allow an information disclosure. Network adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via network access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20712

Severity Rating: Medium

Description: Incomplete cleanup in some UEFI firmware for some Intel(R) reference platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20713

Severity Rating: Medium

Description: Always-incorrect control flow implementation in some firmware for some Intel(R) Xeon(R) processors may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20715

Severity Rating: High

Description: Improper input validation in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT) and some Intel(R) Standard Manageability may allow a denial of service. Network adversary with an unauthenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via network access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20734

Severity Rating: Medium

Description: Improper initialization in some firmware for some Intel(R) Active Management Technology (Intel(R) AMT), and some Intel(R) Standard Manageability may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20760

Severity Rating: Medium

Description: Improper handling of overlap between protected memory ranges in some microcode for some Intel(R) Processors within Ring 0: Hypervisor may allow an escalation of privilege. Authorized adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20775

Severity Rating: Medium

Description: Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20885

Severity Rating: High

Description: Improper authentication in the Intel(R) TDX module for some Intel(R) platforms within Ring 0: Trust Domain may allow an information disclosure and escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (low), integrity (low) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20898

Severity Rating: High

Description: Improper access control in the firmware for some in Alias Checking Trusted Module for some Intel(R) Xeon(R) processors may allow an escalation of privilege. Startup code and SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (high) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20901

Severity Rating: Medium

Description: Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Startup code and smm adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20917

Severity Rating: Medium

Description: Exposure of sensitive information caused by incorrect data forwarding during transient execution for some Intel(R) Processors within Ring 0: Hypervisor and Kernel may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are not present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-6726

Severity Rating: High

Description: An information leakage vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key or TLS authentication key) and falsify other TPM 2.0 attestations with this key. See also TCG VRT0010.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-6727

Severity Rating: Medium

Description: A timing side-channel vulnerability exists in the RSA OAEP decryption implementation. A privileged local attacker with access to the TPM command interface may be able to exploit timing differences to recover information that could allow decryption of ciphertexts encrypted to TPM-managed RSA keys, including the RSA Endorsement Key (EK), including import blobs, credential blobs, and session salts. Under certain conditions, this may also enable the forgery of TPM 2.0 attestations. Refer to TCGVRT0011.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2023-31316

Severity Rating: High

Description: Improperly preserved integrity of hardware configuration state during a power save/restore operation in the AMD Secure Processor (ASP) could allow an attacker with the ability to write outside the trusted memory range (TMR) to change the execution flow of the Video Core Next (VCN) firmware potentially impacting confidentiality, integrity, or availability.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2024-36315

Severity Rating: Medium

Description: Improper enforcement of the LFENCE serialization property may allow an attacker to bypass speculation barriers and potentially disclose sensitive information, potentially resulting in loss of confidentiality.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-15467

Severity Rating: High

Description: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-61971

Severity Rating: Medium

Description: Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to modify MMIO routing configurations, potentially resulting in loss of SEV-SNP guest integrity.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-61972

Severity Rating: High

Description: Missing lock bit protection for NBIO registers could allow a local admin-privileged attacker to gain arbitrary System Management Network (SMN) access, potentially resulting in arbitrary code execution in AMD Secure Processor (ASP) and loss of the SEV-SNP guest's confidentiality and integrity.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-68160

Severity Rating: Medium

Description: Writing large, newline-free data into a BIO chain using the line-buffering filter where the next BIO performs short writes can trigger a heap-based out-of-bounds write. This out-of-bounds write can cause memory corruption which typically results in a crash, leading to Denial of Service for an application.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-69418

Severity Rating: Medium

Description: When using the low-level OCB API directly with AES-NI or other hardware-accelerated code paths, inputs whose length is not a multiple of 16 bytes can leave the final partial block unencrypted and unauthenticated. The trailing 1-15 bytes of a message may be exposed in cleartext on encryption and are not covered by the authentication tag, allowing an attacker to read or tamper with those bytes without detection.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-69419

Severity Rating: High

Description: Calling PKCS12_get_friendlyname() function on a maliciously crafted PKCS#12 file with a BMPString (UTF-16BE) friendly name containing non-ASCII BMP code point can trigger a one byte write before the allocated buffer. The out-of-bounds write can cause a memory corruption which can have various consequences including a Denial of Service.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2025-69421

Severity Rating: High

Description: Processing a malformed PKCS#12 file can trigger a NULL pointer dereference in the PKCS12_item_decrypt_d2i_ex() function. A NULL pointer dereference can trigger a crash which leads to Denial of Service for an application processing PKCS#12 files.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-0438

Severity Rating: Medium

Description: A System Management Mode (SMM) handler could perform a callout to code located in non-SMM/untrusted memory. A highly privileged attacker could, with active user interaction and under high complexity and present preconditions, trigger execution of attacker-controlled code in SMM, potentially compromising the system’s confidentiality, integrity, and availability.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-20716

Severity Rating: High

Description: Improper access control for some Intel(R) Processors within Ring 3: User Applications may allow an escalation of privilege. Simple hardware adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (high) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-22795

Severity Rating: Medium

Description: An invalid or NULL pointer dereference can happen in an application processing a malformed PKCS#12 file. An application processing a malformed PKCS#12 file can be caused to dereference an invalid or NULL pointer on memory read, resulting in a Denial of Service.

 

Common Vulnerabilities or Exposures (CVEID): CVE-2026-22796

Severity Rating: Medium

Description: A type confusion vulnerability exists in the signature verification of signed PKCS#7 data where an ASN1_TYPE union member is accessed without first validating the type, causing an invalid or NULL pointer dereference when processing malformed PKCS#7 data. An application performing signature verification of PKCS#7 data or calling directly the PKCS7_digest_from_attributes() function can be caused to dereference an invalid or NULL pointer when reading, resulting in a Denial of Service.

 

 

* Please go to the "Support" section of the relevant product page to download the updated BIOS.

* For further assistance regarding this issue, please contact your Giga Computing sales representative.