Database/Firmware, BMC & network fabric

Insyde InsydeH2O BmpDecoderDxe: Crafted BMP logo copies data to a chosen address during DXE
CVSS 5.5CVE-2023-40238Firmware, BMC & network fabricLogoFAILcurated
Impact
Crafted BMP logo copies data to a chosen address during DXE — arbitrary write before Secure Boot
Who can reach it
Local, ESP write
What to do
Insyde kernel update shipped through each OEM; the CVSS understates it because the outcome is a firmware implant
References
Related entries
- shim (verify_buffer_authenticode): Out-of-bounds read on a malformed PE file crashes shim and blocks bootCVE-2023-40549 · shim (verify_buffer_authenticode)Medium
- shim (verify_buffer_sbat): Out-of-bounds read in SBAT verification discloses adjacent boot-time memory to an attackerCVE-2023-40550 · shim (verify_buffer_sbat)Medium
- Linux kernel (drivers/infiniband/sw/rxe): Soft-RoCE queue-pair cleanup drains send and receive work queues that aCVE-2023-53528 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- Linux kernel (drivers/infiniband/sw/rxe): If soft-RoCE queue-pair creation fails partway, the unwind path runs cleanupCVE-2023-54028 · Linux kernel (drivers/infiniband/sw/rxe)Medium
- Linux bnxt_re RoCE driver (chip context memory leak): Memory leak in the Broadcom RoCE driver when doorbell BAR mappingCVE-2024-50172 · Linux bnxt_re RoCE driver (chip context memory leak)Medium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core): When the driver runs out of firmware command slots, the workCVE-2025-21662 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.