CVE-2023-40238
07.12.2023, 04:15
A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a specific address during the DXE phase of UEFI execution. This occurs because of an integer signedness error involving PixelHeight and PixelWidth during RLE4/RLE8 compression.Enginsight
| Vendor | Product | Version |
|---|---|---|
| fujitsu | esprimo_d556\/2_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_d6011_firmware | 𝑥 < 1.31.0 |
| fujitsu | esprimo_d6012_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_d7010_firmware | 𝑥 < 1.64.0 |
| fujitsu | esprimo_d7010\/8_firmware | 𝑥 < 1.64.0 |
| fujitsu | esprimo_d7011_firmware | 𝑥 < 1.31.0 |
| fujitsu | esprimo_d7012_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_d7013_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_d738_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_d757_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_d9010_firmware | 𝑥 < 1.64.0 |
| fujitsu | esprimo_d9011_firmware | 𝑥 < 1.31.0 |
| fujitsu | esprimo_d9012_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_d9013_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_d957_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_d957\/e9x\+_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_d958_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_g5010_firmware | 𝑥 < 1.45.0 |
| fujitsu | esprimo_g5011_firmware | 𝑥 < 1.27.0 |
| fujitsu | esprimo_g558_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_g6012_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_g9010_firmware | 𝑥 < 1.45.0 |
| fujitsu | esprimo_g9012_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_g9013_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_k5010\/24_firmware | 𝑥 < 1.64.0 |
| fujitsu | esprimo_k557\/24_firmware | 𝑥 < 1.18.0 |
| fujitsu | esprimo_k558\/24_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_p5010_firmware | 𝑥 < 1.64.0 |
| fujitsu | esprimo_p5011_firmware | 𝑥 < 1.31.0 |
| fujitsu | esprimo_p557_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_p558\/power_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_p6012_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_p7010_firmware | 𝑥 < 1.64.0 |
| fujitsu | esprimo_p7011_firmware | 𝑥 < 1.31.0 |
| fujitsu | esprimo_p7012_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_p7013_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_p757_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_p758_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_p9010_firmware | 𝑥 ≤ 1.64.0 |
| fujitsu | esprimo_p9011_firmware | 𝑥 < 1.31.0 |
| fujitsu | esprimo_p9012_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_p9013_firmware | 𝑥 < 3.08.0 |
| fujitsu | esprimo_p957_firmware | 𝑥 < 1.35.0 |
| fujitsu | lifebook_u9313x_firmware | 𝑥 < 2.12 |
| fujitsu | lifebook_u939_firmware | 𝑥 < 2.23 |
| fujitsu | lifebook_u939x_firmware | 𝑥 < 2.26 |
| fujitsu | lifebook_u9413_firmware | 𝑥 < 2.12 |
| fujitsu | stylistic_q5010_firmware | 𝑥 < 1.38 |
| fujitsu | stylistic_q509_firmware | 𝑥 < 1.37 |
| fujitsu | stylistic_q7310_firmware | 𝑥 < 2.27 |
| fujitsu | stylistic_q7311_firmware | 𝑥 < 2.36 |
| fujitsu | stylistic_q7312_firmware | 𝑥 < 2.17 |
| fujitsu | stylistic_q739_firmware | 𝑥 < 2.21 |
| fujitsu | primequest_3800b_firmware | 𝑥 < 2.23.0 |
| fujitsu | primequest_3800b2_firmware | 𝑥 < 1.67.0 |
| fujitsu | primergy_bx2560_m2_firmware | 𝑥 < 1.21.0 |
| fujitsu | primergy_bx2580_m2_firmware | 𝑥 < 1.21.0 |
| fujitsu | primergy_cx2550_m4_firmware | 𝑥 < 1.51.0 |
| fujitsu | primergy_cx2550_m5_firmware | 𝑥 < 1.25.0 |
| fujitsu | primergy_cx2550_m6_firmware | 𝑥 < 1.34.0 |
| fujitsu | primergy_cx2550_m7_firmware | 𝑥 < 2.6.0 |
| fujitsu | primergy_cx2560_m4_firmware | 𝑥 < 1..51.0 |
| fujitsu | primergy_cx2560_m5_firmware | 𝑥 < 1.34.0 |
| fujitsu | primergy_cx2560_m6_firmware | 𝑥 < 1.34.0 |
| fujitsu | primergy_cx2560_m7_firmware | 𝑥 < 2.2.0 |
| fujitsu | primergy_cx2570_m4_firmware | 𝑥 < 1.51.0 |
| fujitsu | primergy_cx2570_m5_firmware | 𝑥 < 1.25.0 |
| fujitsu | primergy_gx2460_m1_firmware | 𝑥 < 7.11.3 |
| fujitsu | primergy_gx2560_m7_firmware | 𝑥 < 2.6.0 |
| fujitsu | primergy_gx2570_m6_firmware | 𝑥 < 1.9 |
| fujitsu | primergy_rx1330_m3_firmware | 𝑥 < 1.39.0 |
| fujitsu | primergy_rx1330_m4_firmware | 𝑥 < 1.30.0 |
| fujitsu | primergy_rx1330_m5_firmware | 𝑥 < 1.50.0 |
| fujitsu | primergy_rx1440_m2_firmware | 𝑥 < 1.6.0 |
| fujitsu | primergy_rx2450_m1_firmware | 𝑥 < 3.0 |
| fujitsu | primergy_rx2450_m2_firmware | 𝑥 < 1.6.0 |
| fujitsu | primergy_rx2520_m4_firmware | 𝑥 < 1.63.0 |
| fujitsu | primergy_rx2520_m5_firmware | 𝑥 < 1.41.0 |
| fujitsu | primergy_rx2530_m4_firmware | 𝑥 < 1.63.0 |
| fujitsu | primergy_rx2530_m5_firmware | 𝑥 < 1.41.0 |
| fujitsu | esprimo_p958_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_p958\/power_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_p9910_firmware | 𝑥 < 1.64.0 |
| fujitsu | esprimo_q556\/2_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_q556\/2\/d_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_q558_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_q7010_firmware | 𝑥 < 2.20.0 |
| fujitsu | esprimo_q957\/mre_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_q957_firmware | 𝑥 < 1.35.0 |
| fujitsu | esprimo_q958_firmware | 𝑥 < 1.38.0 |
| fujitsu | esprimo_q958\/mre_firmware | 𝑥 < 1.38.0 |
| fujitsu | celsius_c780_firmware | 𝑥 < 1.28.0 |
| fujitsu | celsius_j5010_firmware | 𝑥 < 1.64.0 |
| fujitsu | celsius_j550\/2_firmware | 𝑥 < 1.35.0 |
| fujitsu | celsius_j580_firmware | 𝑥 < 1.38.0 |
| fujitsu | celsius_m7010_firmware | 𝑥 < 1.12.0 |
| fujitsu | celsius_m7010power_firmware | 𝑥 < 1.12.0 |
| fujitsu | celsius_m7010x_firmware | 𝑥 < 1.06.0 |
| fujitsu | celsius_m7010xpower_firmware | 𝑥 < 1.06.0 |
| fujitsu | celsius_r970_firmware | 𝑥 < 1.14.0 |
| fujitsu | celsius_r970b_firmware | 𝑥 < 1.14.0 |
| fujitsu | celsius_r970bpower_firmware | 𝑥 < 1.14.0 |
| fujitsu | celsius_w5010_firmware | 𝑥 < 1.64.0 |
| fujitsu | celsius_w5010\/l_firmware | 𝑥 < 1.64.0 |
| fujitsu | celsius_w5011_firmware | 𝑥 < 1.31.0 |
| fujitsu | celsius_w5012_firmware | 𝑥 < 3.08.0 |
| fujitsu | celsius_w5012-ll_firmware | 𝑥 < 3.08.0 |
| fujitsu | celsius_w570_firmware | 𝑥 < 1.35.0 |
| fujitsu | celsius_w570power_firmware | 𝑥 < 1.35.0 |
| fujitsu | celsius_w570power\+_firmware | 𝑥 < 1.35.0 |
| fujitsu | celsius_w580_firmware | 𝑥 < 1.38.0 |
| fujitsu | celsius_w580power_firmware | 𝑥 < 1.38.0 |
| fujitsu | celsius_w580power\+_firmware | 𝑥 < 1.38.0 |
| fujitsu | celsius_h5511_firmware | 𝑥 < 1.16 |
| fujitsu | celsius_h7510_firmware | 𝑥 < 1.17 |
| fujitsu | celsius_h7613_firmware | 𝑥 < 1.14 |
| fujitsu | celsius_h780_firmware | 𝑥 < 1.23 |
| fujitsu | celsius_h980_firmware | - |
| fujitsu | lifebook_a3510_firmware | 𝑥 < 1.16 |
| fujitsu | lifebook_a3511_firmware | - |
| fujitsu | primergy_rx2530_m6_firmware | 𝑥 < 1.28.0 |
| fujitsu | primergy_rx2530_m7_firmware | 𝑥 < 2.8.0 |
| fujitsu | primergy_rx2540_m4_firmware | 𝑥 < 1.63.0 |
| fujitsu | primergy_rx2540_m5_firmware | 𝑥 < 1.41.0 |
| fujitsu | primergy_rx2540_m6_firmware | 𝑥 < 1.28.0 |
| fujitsu | primergy_rx2540_m7_firmware | 𝑥 < 2.8.0 |
| fujitsu | primergy_rx4770_m3_firmware | 𝑥 < 1.27.0 |
| fujitsu | primergy_rx4770_m4_firmware | 𝑥 < 1.63.0 |
| fujitsu | primergy_rx4770_m5_firmware | 𝑥 < 1.41.0 |
| fujitsu | primergy_rx4770_m6_firmware | 𝑥 < 1.23.0 |
| fujitsu | primergy_rx4770_m7_firmware | 𝑥 < 2.8.0 |
| fujitsu | primergy_rx8770_m7_firmware | 𝑥 < 2.8.0 |
| fujitsu | primergy_tx1310_m3_firmware | 𝑥 < 1.39.0 |
| fujitsu | primergy_tx1310_m5_firmware | 𝑥 < 1.50.0 |
| fujitsu | primergy_tx1320_m3_firmware | 𝑥 < 1.39.0 |
| fujitsu | primergy_tx1320_m4_firmware | 𝑥 < 1.30.0 |
| fujitsu | primergy_tx1320_m5_firmware | 𝑥 < 1.50.0 |
| fujitsu | primergy_tx1330_m3_firmware | 𝑥 < 1.39.0 |
| fujitsu | primergy_tx1330_m4_firmware | 𝑥 < 1.30.0 |
| fujitsu | primergy_tx1330_m5_firmware | 𝑥 < 1.50.0 |
| fujitsu | primergy_tx2550_m4_firmware | 𝑥 < 1.63.0 |
| fujitsu | primergy_tx2550_m5_firmware | 𝑥 < 1.41.0 |
| fujitsu | primergy_tx2550_m7_firmware | 𝑥 < 2.5.0 |
| fujitsu | lifebook_e4411_firmware | 𝑥 < 2.40 |
| fujitsu | lifebook_e4511_firmware | 𝑥 < 2.40 |
| fujitsu | lifebook_e5410_firmware | 𝑥 < 2.33 |
| fujitsu | lifebook_e5411_firmware | 𝑥 < 2.40 |
| fujitsu | lifebook_e5412_firmware | 𝑥 < 2.33 |
| fujitsu | lifebook_e5412\/mtc_firmware | 𝑥 < 2.33 |
| fujitsu | lifebook_e5413_firmware | 𝑥 < 2.15 |
| fujitsu | lifebook_e549_firmware | 𝑥 < 2.25 |
| fujitsu | lifebook_e5510_firmware | 𝑥 < 2.33 |
| fujitsu | lifebook_e5511_firmware | 𝑥 < 2.40 |
| fujitsu | lifebook_e5512_firmware | 𝑥 < 2.33 |
| fujitsu | lifebook_e5513_firmware | 𝑥 < 2.15 |
| fujitsu | lifebook_e559_firmware | 𝑥 < 2.25 |
| fujitsu | lifebook_e736_firmware | - |
| fujitsu | lifebook_e736_vpro_firmware | - |
| fujitsu | lifebook_e746_firmware | - |
| fujitsu | lifebook_e746_vpro_firmware | - |
| fujitsu | lifebook_t939_firmware | 𝑥 < 2.20 |
| fujitsu | lifebook_u5313x_firmware | 𝑥 < 2.08 |
| fujitsu | lifebook_u729_firmware | 𝑥 < 2.30 |
| fujitsu | lifebook_u729x_firmware | 𝑥 < 2.21 |
| fujitsu | lifebook_u7310_firmware | 𝑥 < 2.29 |
| fujitsu | lifebook_u7311_firmware | 𝑥 < 2.44 |
| fujitsu | lifebook_u7312_firmware | 𝑥 < 2.33 |
| fujitsu | lifebook_u7313_firmware | 𝑥 < 2.15 |
| fujitsu | lifebook_u7410_firmware | 𝑥 < 2.29 |
| fujitsu | lifebook_u7411_firmware | 𝑥 < 2.44 |
| fujitsu | lifebook_u7412_firmware | 𝑥 < 2.33 |
| fujitsu | lifebook_u7413_firmware | 𝑥 < 2.15 |
| fujitsu | lifebook_u749_firmware | 𝑥 < 2.30 |
| fujitsu | lifebook_u7510_firmware | 𝑥 < 2.29 |
| fujitsu | lifebook_u7511_firmware | 𝑥 < 2.44 |
| fujitsu | lifebook_u7512_firmware | 𝑥 < 2.33 |
| fujitsu | lifebook_u759_firmware | 𝑥 < 2.30 |
| fujitsu | lifebook_u7613_firmware | 𝑥 < 2.15 |
| fujitsu | lifebook_u9310_firmware | 𝑥 < 2.27 |
| fujitsu | lifebook_u9310x_firmware | 𝑥 < 2.27 |
| fujitsu | lifebook_u9311_firmware | 𝑥 < 2.53 |
| fujitsu | lifebook_u9312_firmware | 𝑥 < 2.31 |
| fujitsu | lifebook_u9312x_firmware | 𝑥 < 2.21 |
| insyde | insydeh2o | 5.2 ≤ 𝑥 < 5.2.05.28.47 |
| insyde | insydeh2o | 5.3 ≤ 𝑥 < 5.3.05.37.47 |
| insyde | insydeh2o | 5.4 ≤ 𝑥 < 5.4.05.45.47 |
| insyde | insydeh2o | 5.5 ≤ 𝑥 < 5.5.05.53.47 |
| insyde | insydeh2o | 5.6 ≤ 𝑥 < 5.6.05.60.47 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration