Back to Database
Status published
High
CVE-2021-38578
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when...
Vulnerability Description
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-38578
Credits & Attribution
No credits recorded in the NVD database.
References
More from TianoCore
View All →CVE-2025-3770
SMM IDT Privilege Escalation Vulnerability
High
7
CVE-2025-2296
Un-verified kernel bypass Secure Boot mechanism in direct boot mode
High
8.4
CVE-2025-2295
Potential iSCSI R2T PDU Vulnerability
Low
3.5
CVE-2024-38805
iSCSI Remote Memory Corruption and Denial of Service
Medium
6.3
CVE-2024-38798
Uncleared password keystrokes in circular queue can lead to information disclosure or escalation of privilege
Medium
5.8
Affected Vendor
TianoCore
View all reports →Affected Software
EDK II
Vulnerable Versions:
edk2-stable202208
Timeline
Official Publish:
March 3rd, 2022
Last Modified:
November 3rd, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.