GPU VulnDB

Database/Firmware, BMC & network fabric

Insyde InsydeH2O BmpDecoderDxe: Crafted BMP logo copies data to a chosen address during DXE

CVE-2023-40238Firmware, BMC & network fabricLogoFAILcurated

Impact

Crafted BMP logo copies data to a chosen address during DXE — arbitrary write before Secure Boot

Who can reach it

Local, ESP write

What to do

Insyde kernel update shipped through each OEM; the CVSS understates it because the outcome is a firmware implant

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.