668
VMScore

CVE-2021-38578

Published: 03/03/2022 Updated: 02/08/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tianocore edk2

insyde kernel 5.0

insyde kernel 5.2

insyde kernel 5.3

insyde kernel 5.4

insyde kernel 5.5

insyde kernel 5.1

Vendor Advisories

Debian Bug report logs - #1014468 edk2: CVE-2021-38576 CVE-2021-38577 CVE-2021-38578 Package: src:edk2; Maintainer for src:edk2 is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Reported by: Moritz Mühlenhoff <jmm@inutilorg> Date: Wed, 6 Jul 2022 15:21:02 UTC Severity: normal Tags: security, upstream ...
Synopsis Important: OpenShift Container Platform 4132 bug fix and security update Type/Severity Security Advisory: Important Topic Red Hat OpenShift Container Platform release 4132 is now available with updates to packages and images that fix several bugs and add enhancementsThis release includes a security update for Red Hat OpenShift C ...