cbcvebase.
CVE-2021-38578
published 2022-03-03

CVE-2021-38578: Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

Affected

18 ranges
VendorProductVersion rangeFixed in
debianedk2< edk2 2022.11-1 (bookworm)edk2 2022.11-1 (bookworm)
insydekernel
insydekernel
insydekernel
insydekernel
insydekernel
insydekernel
msrccbl2_qemu_6.2.0-24_on_cbl_mariner_2.0
tianocoreedk2<= 202202
tianocoreedk2>= 0 < 2020.11-2+deb11u32020.11-2+deb11u3
tianocoreedk2>= 0 < 2022.11-12022.11-1
tianocoreedk2>= 0 < 2022.11-12022.11-1
tianocoreedk2>= 0 < 2022.11-12022.11-1
tianocoreedk2>= 0 < 0~20191122.bd85bf54-2ubuntu3.60~20191122.bd85bf54-2ubuntu3.6
tianocoreedk2>= 0 < 2022.02-3ubuntu0.22.04.32022.02-3ubuntu0.22.04.3
tianocoreedk2>= 0 < 0~20160408.ffea0a2c-2ubuntu0.2+esm30~20160408.ffea0a2c-2ubuntu0.2+esm3
tianocoreedk2>= 0 < 0~20180205.c0d9813c-2ubuntu0.3+esm20~20180205.c0d9813c-2ubuntu0.3+esm2
tianocoreedk_ii

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL