Buffer Underwrite ('Buffer Underflow')
CVE-2021-38575
Summary
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
- HIGH
- NETWORK
- HIGH
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-124 - Buffer Underwrite ('Buffer Underflow')
The software writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.
References
Advisory Timeline
- Published