CVE-2021-38578
published 2022-03-03CVE-2021-38578: Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
PriorityP342critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
1.01%
59.6th percentile
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | edk2 | < edk2 2022.11-1 (bookworm) | edk2 2022.11-1 (bookworm) |
| insyde | kernel | — | — |
| insyde | kernel | — | — |
| insyde | kernel | — | — |
| insyde | kernel | — | — |
| insyde | kernel | — | — |
| insyde | kernel | — | — |
| msrc | cbl2_qemu_6.2.0-24_on_cbl_mariner_2.0 | — | — |
| tianocore | edk2 | <= 202202 | — |
| tianocore | edk2 | >= 0 < 2020.11-2+deb11u3 | 2020.11-2+deb11u3 |
| tianocore | edk2 | >= 0 < 2022.11-1 | 2022.11-1 |
| tianocore | edk2 | >= 0 < 2022.11-1 | 2022.11-1 |
| tianocore | edk2 | >= 0 < 2022.11-1 | 2022.11-1 |
| tianocore | edk2 | >= 0 < 0~20191122.bd85bf54-2ubuntu3.6 | 0~20191122.bd85bf54-2ubuntu3.6 |
| tianocore | edk2 | >= 0 < 2022.02-3ubuntu0.22.04.3 | 2022.02-3ubuntu0.22.04.3 |
| tianocore | edk2 | >= 0 < 0~20160408.ffea0a2c-2ubuntu0.2+esm3 | 0~20160408.ffea0a2c-2ubuntu0.2+esm3 |
| tianocore | edk2 | >= 0 < 0~20180205.c0d9813c-2ubuntu0.3+esm2 | 0~20180205.c0d9813c-2ubuntu0.3+esm2 |
| tianocore | edk_ii | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_debian7.4HIGH
vendor_msrc7.4HIGH
vendor_redhat7.4HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
edk2 vulnerabilities
osv·2024-10-10·CVSS 5.5
CVE-2019-0161 [MEDIUM] edk2 vulnerabilities
edk2 vulnerabilities
It was discovered that EDK II did not check the buffer length in XHCI,
which could lead to a stack overflow. A local attacker could potentially
use this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-0161)
Laszlo Ersek discovered that EDK II incorrectly handled recursion. A
remote attacker could possibly use this issue to cause EDK II to consume
resources, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2021-28210)
Satoshi Tanda discovered that EDK II incorrectly handled decompressing
certain images. A remote attacker could use this issue to cause EDK II to
crash, resulting in a denial of service, or possibly execute arbitrary
code. This issue only aff
GHSA
GHSA-grqq-3jqg-g95p: Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize
ghsa_unreviewed·2022-03-04
CVE-2021-38578 [CRITICAL] CWE-124 GHSA-grqq-3jqg-g95p: Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
OSV
CVE-2021-38578: Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize
osv·2022-03-03·CVSS 9.8
CVE-2021-38578 [CRITICAL] CVE-2021-38578: Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Ubuntu
EDK II vulnerabilities
vendor_ubuntu·2024-10-10·CVSS 5.5
CVE-2021-38578 [MEDIUM] EDK II vulnerabilities
Title: EDK II vulnerabilities
Summary: Several security issues were fixed in EDK II.
It was discovered that EDK II did not check the buffer length in XHCI,
which could lead to a stack overflow. A local attacker could potentially
use this issue to cause a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2019-0161)
Laszlo Ersek discovered that EDK II incorrectly handled recursion. A
remote attacker could possibly use this issue to cause EDK II to consume
resources, leading to a denial of service. This issue only affected
Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2021-28210)
Satoshi Tanda discovered that EDK II incorrectly handled decompressing
certain images. A remote attacker could use this issue to cause EDK II to
crash, resulting in a denial of
CISA ICS
Siemens RUGGEDCOM APE1808 Product Family
cisa_ics·2023-09-14
Siemens RUGGEDCOM APE1808 Product Family
ICS Advisory
##
Siemens RUGGEDCOM APE1808 Product Family
Release DateSeptember 14, 2023
Alert CodeICSA-23-257-04
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 8.2
- ATTENTION: Low Attack Complexity
- Vendor: Siemens
- Equipment: RUGGEDCOM APE1808 Product Family
- Vulnerabilities: Exposure of Sensitive Information to an Unauthorized Actor, Buffer Underflow, Classic Buffer Overflow, Time-of-check Time-of-use Race Condition, Out-of-bounds Read, Im
Microsoft
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
vendor_msrc·2022-03-08·CVSS 7.4
CVE-2021-38578 [HIGH] CWE-124 Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
TianoCore: TianoCore
Customer Action Required: Yes
Red Hat
edk2: integer underflow in SmmEntryPoint function leads to potential SMM privilege escalation
vendor_redhat·2022-03-03·CVSS 7.4
CVE-2021-38578 [HIGH] CWE-124 edk2: integer underflow in SmmEntryPoint function leads to potential SMM privilege escalation
edk2: integer underflow in SmmEntryPoint function leads to potential SMM privilege escalation
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
A flaw was found in edk2. A integer underflow in the SmmEntryPoint function leads to a write into the SMM region allowing a local attacker with administration privileges on the system to execute code within the SMM privileged context. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.
Package: ovmf (Red Hat Enterprise Linux 7) - Out of support scope
Package: edk2 (Red Hat Enterprise Linux 8) - Affected
Debian
CVE-2021-38578: edk2 - Existing CommBuffer checks in SmmEntryPoint will not catch underflow when comput...
vendor_debian·2021·CVSS 7.4
CVE-2021-38578 [HIGH] CVE-2021-38578: edk2 - Existing CommBuffer checks in SmmEntryPoint will not catch underflow when comput...
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Scope: local
bookworm: resolved (fixed in 2022.11-1)
bullseye: resolved (fixed in 2020.11-2+deb11u3)
forky: resolved (fixed in 2022.11-1)
sid: resolved (fixed in 2022.11-1)
trixie: resolved (fixed in 2022.11-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-03-03
Published