Buffer overflow in edk2 - CVE-2021-38575

 

Buffer overflow in edk2 - CVE-2021-38575

Published: September 14, 2021


Vulnerability identifier: #VU56490
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-38575
CWE-ID: CWE-119
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the IScsiHexToBin() function in NetworkPkg/IScsiDxe. A remote attacker with ability to inject data into communication between edk2 and the iSCSI target can execute arbitrary code on the target system.



Affected software

edk2
Vostro 15 3535
Vostro 14 3435
Inspiron 15 3535
Inspiron 14 5435
Inspiron 16 7635 2-in-1
Inspiron 16 5635
Inspiron 14 7435 2-in-1
Vostro 16 5635
Alienware m15 R7 AMD
Alienware m17 R5 AMD
Dell G15 5525
Inspiron 14 7425 2-in-1
Inspiron 5425
Vostro 5625
Vostro 3425
Inspiron 15 3525
Vostro 3525
Inspiron 5505
Inspiron 5405
Dell G15 5515
Inspiron 7405 2-in-1
Alienware m15 Ryzen Edition R5
Inspiron 5415
Inspiron 3585
Inspiron 3785
Vostro 3405
Inspiron 3515
Inspiron 3505
Vostro 3515
Dell G5 5505
Vostro 5415
Inspiron 5515
Inspiron 7415 2-in-1
Vostro 5515
Red Hat Container Native Virtualization
OpenShift Virtualization
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
openEuler
Ubuntu
qemu-efi-arm (Ubuntu package)
qemu-efi (Ubuntu package)
ovmf (Ubuntu package)
qemu-efi-aarch64 (Ubuntu package)
ovmf-ia32 (Ubuntu package)
edk2
edk2-devel
edk2-debugsource
edk2-debuginfo
python3-edk2-devel
edk2-help
edk2-aarch64
edk2-ovmf
edk2 (Red Hat package)

How to mitigate CVE-2021-38575

Install updates from vendor's website.

edk2 - update to edk2-stable202108
qemu-efi-arm (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.3, 2020.11-4ubuntu0.1
qemu-efi (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.3, 2020.11-4ubuntu0.1
ovmf (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.3, 2020.11-4ubuntu0.1
qemu-efi-aarch64 (Ubuntu package) - addressed in versions 0~20191122.bd85bf54-2ubuntu3.3, 2020.11-4ubuntu0.1
Vostro 15 3535 - update to 1.6.0
Vostro 14 3435 - update to 1.6.0
Inspiron 15 3535 - update to 1.6.0
Inspiron 14 5435 - update to 1.6.1
Inspiron 16 7635 2-in-1 - update to 1.6.1
Inspiron 16 5635 - update to 1.6.1
Inspiron 14 7435 2-in-1 - update to 1.6.1
Vostro 16 5635 - update to 1.6.1
Alienware m15 R7 AMD - update to 1.11.1
Alienware m17 R5 AMD - update to 1.11.1
Dell G15 5525 - update to 1.11.1
Inspiron 14 7425 2-in-1 - update to 1.12.1
Inspiron 5425 - update to 1.12.1
Vostro 5625 - update to 1.12.1
Vostro 3425 - update to 1.13.0
Inspiron 15 3525 - update to 1.13.0
Vostro 3525 - update to 1.13.0
Inspiron 5505 - update to 1.13.2
Inspiron 5405 - update to 1.13.2
Dell G15 5515 - update to 1.14.0
Inspiron 7405 2-in-1 - update to 1.14.2
Alienware m15 Ryzen Edition R5 - update to 1.15.0
Inspiron 5415 - update to 1.15.0
Inspiron 3585 - update to 1.15.0
Inspiron 3785 - update to 1.15.0
Vostro 3405 - update to 1.15.1
Inspiron 3515 - update to 1.15.1
Inspiron 3505 - update to 1.15.1
Vostro 3515 - update to 1.15.1
Dell G5 5505 - update to 1.17.2
Vostro 5415 - update to 1.18.1
Inspiron 5515 - update to 1.18.1
Inspiron 7415 2-in-1 - update to 1.18.1
Vostro 5515 - update to 1.18.1
OpenShift Virtualization - addressed in versions 2.6.7, 4.8.2
ovmf-ia32 (Ubuntu package) - update to 2020.11-4ubuntu0.1
edk2 - update to 202002-6
edk2-devel - update to 202002-6
edk2-debugsource - update to 202002-6
edk2-debuginfo - update to 202002-6
python3-edk2-devel - update to 202002-6
edk2-help - update to 202002-6
edk2-aarch64 - update to 202002-6
edk2-ovmf - update to 202002-6
edk2 (Red Hat package) - addressed in versions 20190308git89910a39dcfd-6.el8_1.1, 20190829git37eef91017ad-9.el8_2.1, 20200602gitca407c7246bf-4.el8_4.2
edk2-aarch64 - addressed in versions 20190829git37eef91017ad-9, 20200602gitca407c7246bf-4
edk2-ovmf - addressed in versions 20190829git37eef91017ad-9, 20200602gitca407c7246bf-4

External References

Related Security Bulletins