CVE Vulnerabilities

CVE-2021-38575

Buffer Underwrite ('Buffer Underflow')

Published: Dec 01, 2021 | Modified: Nov 03, 2025
CVSS 3.x
8.1
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.1 IMPORTANT
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.

Weakness

The product writes to a buffer using an index or pointer that references a memory location prior to the beginning of the buffer.

Affected Software

NameVendorStart VersionEnd Version
Edk2Tianocore*202105 (including)
Red Hat Enterprise Linux 8RedHatedk2-0:20200602gitca407c7246bf-4.el8_4.2*
Red Hat Enterprise Linux 8.1 Extended Update SupportRedHatedk2-0:20190308git89910a39dcfd-6.el8_1.1*
Red Hat Enterprise Linux 8.2 Extended Update SupportRedHatedk2-0:20190829git37eef91017ad-9.el8_2.1*
Red Hat Virtualization 4 for Red Hat Enterprise Linux 8RedHatredhat-virtualization-host-0:4.4.7-20210804.0.el8_4*
Edk2Ubuntubionic*
Edk2Ubuntuesm-apps/bionic*
Edk2Ubuntuesm-apps/xenial*
Edk2Ubuntuesm-infra/focal*
Edk2Ubuntufocal*
Edk2Ubuntuhirsute*
Edk2Ubuntutrusty*
Edk2Ubuntuupstream*
Edk2Ubuntuxenial*

Potential Mitigations

References