CVE-2021-42059: Buffer Overflow
An issue was discovered in Insyde InsydeH2O Kernel 5.0 before 05.08.41, Kernel 5.1 before 05.16.41, Kernel 5.2 before 05.26.41, Kernel 5.3 before 05.35.41, and Kernel 5.4 before 05.42.20. A stack-based buffer overflow leads toarbitrary code execution in UEFI DisplayTypeDxe DXE driver.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-42059.
What is the severity of CVE-2021-42059?
The severity of CVE-2021-42059 is high, with a severity value of 6.7.
Which software versions are affected by CVE-2021-42059?
Insyde InsydeH2O Kernel versions 5.0 through 5.4 are affected by CVE-2021-42059.
What is the description of CVE-2021-42059?
CVE-2021-42059 is a stack-based buffer overflow vulnerability in the UEFI DisplayTypeDxe DXE driver in Insyde InsydeH2O Kernel versions 5.0 through 5.4, which can lead to arbitrary code execution.
Are Siemens Simatic Field PG M5 and M6 affected by CVE-2021-42059?
No, Siemens Simatic Field PG M5 and M6 are not affected by CVE-2021-42059.