VYPR
Unrated severityNVD Advisory· Published Dec 7, 2023· Updated Feb 25, 2026

CVE-2023-40238

CVE-2023-40238

Description

A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a specific address during the DXE phase of UEFI execution. This occurs because of an integer signedness error involving PixelHeight and PixelWidth during RLE4/RLE8 compression.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Insyde/InsydeH2Odescription
  • Insyde/BIOSllm-fuzzy
    Range: 5.2 < 05.28.47 / 5.3 < 05.37.47 / 5.4 < 05.45.47 / 5.5 < 05.53.47 / 5.6 < 05.60.47

Patches

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

5

News mentions

0

No linked articles in our index yet.