BRLY-LOGOFAIL-2023-009
Out-of-bounds Read in DXE driver.
CVE ID
CVE-2023-40238
Vendors Affected
LogoFAIL
Products Affected
JpegDecoderDxe
Summary
BINARLY efiXplorer team has discovered a OOB Read vulnerability in DXE driver. Improper loop exit condition will lead to OOB Read from ImagePtr during JPEG file processing in Insyde firmware.
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks, and chart a path to post-quantum readiness.
Potential Impact
This vulnerability will not lead to exploitation, however, it may lead to unexpected behaviour during GIF file processing.
Image preview
Vulnerability Information
- BINARLY internal vulnerability identifier: BRLY-LOGOFAIL-2023-009
- Insyde PSIRT assigned CVE identifier: CVE-2023-40238
- CVSS v3.1: 3.2 Low AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:L/A:N
Image preview
Get started today, Ship and Buy Software You Can Prove Is Safe
Book a live tour to watch Binarly validate SBOM/CBOM, surface exploitable risks with reachability and exploitation maturity scoring, and chart a measurable path to post-quantum readiness.