VulnerabilityModified
CVE-2021-26314
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in…
MEDIUM 5.5EPSS 0.61%
Does this matter?
Lower severity and a low EPSS score (0.61%). Track it; it rarely justifies an emergency change on its own.
Description
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 0.61% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-208, CWE-203
- Affected
- xen/xen · arm/cortex-a72 · broadcom/bcm2711 · intel/core i7-10700k · intel/core i7-7700k · intel/core i9-9900k · intel/xeon silver 4214 · fedoraproject/fedora
- Source
- psirt@amd.com
References
- http://www.openwall.com/lists/oss-security/2021/06/09/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/06/10/1Exploit, Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H36U6CNREC436W6GYO7QUMJIVEA35SCV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVA2NY26MMXOODUMYZN5DCU3FXMBMBOB/
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1003Vendor Advisory
- http://www.openwall.com/lists/oss-security/2021/06/09/2Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2021/06/10/1Exploit, Mailing List, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H36U6CNREC436W6GYO7QUMJIVEA35SCV/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVA2NY26MMXOODUMYZN5DCU3FXMBMBOB/
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1003Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.