BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Critical DMA Boot Vulnerability Hits ASRock, ASUS, GIGABYTE, MSI Boards

Critical DMA Vulnerabilities in ASRock, ASUS, GIGABYTE, and MSI Motherboards Enable Pre-OS Memory Attacks; Firmware Updates Urgently Required

  • Multiple motherboard models from major vendors have a vulnerability allowing direct memory access (DMA) attacks during early boot.
  • The issue involves failure to properly enable the input–output memory management unit (IOMMU), despite firmware indicating active DMA protection.
  • The flaw enables physical attackers to read or modify system memory before the operating system loads.
  • Four vulnerabilities impacting ASRock, ASUS, GIGABYTE, and MSI motherboards have been identified, each with a CVSS score of 7.0.
  • Firmware updates to fix the IOMMU initialization and enforce DMA protections are now available and should be applied promptly.

Certain motherboards from ASRock, ASUSTeK Computer, GIGABYTE, and MSI are exposed to security vulnerabilities that allow direct memory access (DMA) attacks during the early boot phase. These flaws were identified in models implementing the Unified Extensible Firmware Interface (UEFI) and the input–output memory management unit (IOMMU). The vulnerabilities were publicly reported on December 19, 2025.

- Advertisement -

UEFI is firmware designed to initialize hardware and load the operating system, while IOMMU restricts peripheral devices from unauthorized memory access. The issue involves a mismatch between the firmware’s indication that DMA protection is active and the actual failure to correctly initialize IOMMU during boot. According to the CERT Coordination Center (CERT/CC), this gap enables a malicious PCIe device with physical access to read or manipulate system memory before OS-level protections are in place. This undermines boot process integrity and could expose sensitive data or allow pre-boot code injection.

The identified vulnerabilities include:

  • CVE-2025-14304 affecting ASRock boards using Intel 500–800 series chipsets.
  • CVE-2025-11901 impacting ASUS motherboards with Intel Z490 to W790 series chipsets.
  • CVE-2025-14302 targeting GIGABYTE models with Intel Z890 to W790 and AMD X870 to TRX50 series chipsets (a fix for TRX50 is planned for Q1 2026).
  • CVE-2025-14303 found in MSI motherboards using Intel 600 and 700 series chipsets.

Each vulnerability is rated with a Common Vulnerability Scoring System (CVSS) score of 7.0, indicating a high severity level.

Affected vendors have released firmware updates addressing the proper initialization of IOMMU and enforcement of DMA protections during boot. Users and system administrators are strongly encouraged to apply these updates immediately. “In environments where physical access cannot be fully controlled or relied on, prompt patching and adherence to hardware security best practices are especially important,” stated CERT/CC. The organization also emphasized that correct firmware configuration is critical even for systems outside of data center use, given the role of IOMMU in virtualization and cloud environments.

- Advertisement -

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Russia-linked crypto exchange Grinex shuts down after $13M hack

The sanctioned Russia-linked crypto exchange Grinex has halted operations after a major hack resulted...

Hayes: U.S.-Iran Conflict May Tank Bitcoin Before Liquidity Surge

Arthur Hayes described markets as being in a 'no trade zone' due to geopolitical...

Justin Sun decries “tyranny” in Trump-linked WLFI vote

World Liberty Financial proposed burning 4.5 billion WLFI tokens and restructuring vesting for 62...

Crypto Market-Maker Deal Disclosures Virtually Absent

Market-making arrangements are disclosed by fewer than 1% of crypto protocols, a rate dramatically...

New Ukraine Cyberattack Targets Government, Healthcare Data

Ukraine's CERT-UA exposed a malware campaign targeting government and healthcare bodies, culminating in a...

Must Read

What Is the Dencun Upgrade for Ethereum?

The Dencun Upgrade for Ethereum is poised to revolutionize the blockchain landscape, offering improved scalability, efficiency, and groundbreaking features. Set to launch at the...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading