Insyde's Security Pledge

Recent Security Advisories

INSYDE-SA-2022026

Product

CVSS Score

Original Date

Last Revised

InsydeH2O

6.7

2022-02-21

Summary

Error in handling the PlatformLangCodes UEFI variable could cause a buffer overflow, leading to resource exhaustion and failure.

Vulnerability Details

CVSS Vector: CVSS:3.1/AV:P/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:L

CVE-2021-43614

This issue corresponds to CVE-2021-43614. It affects the VariableEditSmm driver. This driver is part of an InsydeH2O feature, not the kernel.

Solution Information

It was fixed in version 01.01.04.0008 of the feature.

Acknowledgements

Revision History

Revision #

Date

Description

1

2022-02-21

Initial Release