CVE-2021-28216
published 2021-08-05CVE-2021-28216: BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
PriorityP434high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.42%
34.4th percentile
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | edk2 | < edk2 2021.11~rc1-1 (bookworm) | edk2 2021.11~rc1-1 (bookworm) |
| msrc | cbl2_qemu_6.2.0-24_on_cbl_mariner_2.0 | — | — |
| tianocore | edk2 | >= 0 < 2020.11-2+deb11u3 | 2020.11-2+deb11u3 |
| tianocore | edk2 | >= 0 < 2021.11~rc1-1 | 2021.11~rc1-1 |
| tianocore | edk2 | >= 0 < 2021.11~rc1-1 | 2021.11~rc1-1 |
| tianocore | edk2 | >= 0 < 2021.11~rc1-1 | 2021.11~rc1-1 |
| tianocore | edk_ii | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
osv7.8HIGH
vendor_debian7.8HIGH
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
vendor_msrc·2021-08-10·CVSS 7.8
CVE-2021-28216 [HIGH] CWE-587 BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
TianoCore: TianoCore
C
Debian
CVE-2021-28216: edk2 - BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend se...
vendor_debian·2021·CVSS 7.8
CVE-2021-28216 [HIGH] CVE-2021-28216: edk2 - BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend se...
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
Scope: local
bookworm: resolved (fixed in 2021.11~rc1-1)
bullseye: resolved (fixed in 2020.11-2+deb11u3)
forky: resolved (fixed in 2021.11~rc1-1)
sid: resolved (fixed in 2021.11~rc1-1)
trixie: resolved (fixed in 2021.11~rc1-1)
GHSA
GHSA-6wgv-vj43-rpr5: BootPerformanceTable pointer is read from an NVRAM variable in PEI
ghsa_unreviewed·2022-05-24
CVE-2021-28216 [HIGH] CWE-587 GHSA-6wgv-vj43-rpr5: BootPerformanceTable pointer is read from an NVRAM variable in PEI
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
OSV
CVE-2021-28216: BootPerformanceTable pointer is read from an NVRAM variable in PEI
osv·2021-08-05·CVSS 7.8
CVE-2021-28216 [HIGH] CVE-2021-28216: BootPerformanceTable pointer is read from an NVRAM variable in PEI
BootPerformanceTable pointer is read from an NVRAM variable in PEI. Recommend setting PcdFirmwarePerformanceDataTableS3Support to FALSE.
No detection rules found.
No public exploits indexed.
Qualys
Remediate Your Vulnerable Lenovo Systems with Qualys Custom Assessment and Remediation
blogs_qualys·2022-09-28·CVSS 7.8
CVE-2021-28216 [HIGH] Remediate Your Vulnerable Lenovo Systems with Qualys Custom Assessment and Remediation
## Table of Contents
How Qualys Can Help
Conclusion
Try It for Free
Read More:
Contributors
Lenovo disclosed Multi-Vendor BIOS Security Vulnerabilities in September 2022 that affect multiple Lenovo devices. These are high severity vulnerabilities that have the potential of resulting in information disclosure, privilege escalation, and denial of service. Here are the related CVEs:
CVE-2021-28216 – Tianocore reported a fixed pointer vulnerability in TianoCore EDK II BIOS that may allow an attacker with local access and elevated privileges to execute arbitrary code
CVE-2022-40137 – A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code
CVE-2022-40134 – An information leak vulnerability i
Qualys
Remediate Your Vulnerable Lenovo Systems with Qualys Custom Assessment and Remediation | Qualys
blogs_qualys·2022-09-28·CVSS 7.8
CVE-2021-28216 [HIGH] Remediate Your Vulnerable Lenovo Systems with Qualys Custom Assessment and Remediation | Qualys
#### Table of Contents
- How Qualys Can Help
- Conclusion
- Try It for Free
- Read More:
- Contributors
Lenovo disclosed Multi-Vendor BIOS Security Vulnerabilities in September 2022 that affect multiple Lenovo devices. These are high severity vulnerabilities that have the potential of resulting in information disclosure, privilege escalation, and denial of service. Here are the related CVEs:
- CVE-2021-28216 – Tianocore reported a fixed pointer vulnerability in TianoCore EDK II BIOS that may allow an attacker with local access and elevated privileges to execute arbitrary code
- CVE-2022-40137 – A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code
- CVE-2022-40134 – An information leak vu
2021-08-05
Published