A bit more on this:
https://firmwaresecurity.com/2016/07/05/4047/
Lenovo has updated their support document. The initial version had no technical details. The update now has a huge list of models which are affected or not. The researcher also mentions that an update from the vendor is expected next month. I’m still waiting to see the IBV’s and other OEMs responses to this.
https://support.lenovo.com/us/en/solutions/LEN-8324