Insyde Security Advisory 2022026

Insyde ID Advisory Category Impact of Vulnerability Severity Rating Original Date Last Revised
INSYDE-SA-2022026 Software CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L 6.7 02/21/2022 02/21/2022

Summary:

Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.

Vulnerability Details

CVE-2021-43614

This issue corresponds to CVE-2021-43614. It affects the VariableEditSmm driver. This driver is part of an InsydeH2O feature, not the kernel. It was fixed in version 01.01.04.0008 of the feature.

Revision History:

Revision Date Description
1.0 02/21/2022 Initial Release
- - -

Return to Insyde's Security Pledge