BRLY-LOGOFAIL-2023-009
Out-of-bounds Read in DXE driver.
CVE ID
CVE-2023-40238
Vendors Affected
LogoFAIL
Products Affected
JpegDecoderDxe
Summary
BINARLY efiXplorer team has discovered a OOB Read vulnerability in DXE driver. Improper loop exit condition will lead to OOB Read from ImagePtr during JPEG file processing in Insyde firmware.
Image preview
Potential Impact
This vulnerability will not lead to exploitation, however, it may lead to unexpected behaviour during GIF file processing.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-LOGOFAIL-2023-009
- Insyde PSIRT assigned CVE identifier: CVE-2023-40238
- CVSS v3.1: 3.2 Low AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
Image preview
See if you are impacted now with our Firmware Vulnerability Scanner
Find Vulnerabilities, Generate SBOMs & CBOMs