SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26342

The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents.

LOW 3.3EPSS 0.22%

Does this matter?

Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.

Description

In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV-SNP guest VMs are not impacted by this vulnerability.

CVSS 3.1
3.3 LOWCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS
0.22% probability · 13th percentile
CISA KEV
Not listed
Affected
amd/epyc 7763 firmware · amd/epyc 7713p firmware · amd/epyc 7713 firmware · amd/epyc 7663 firmware · amd/epyc 7643 firmware · amd/epyc 75f3 firmware · amd/epyc 7543p firmware · amd/epyc 7543 firmware · amd/epyc 7513 firmware · amd/epyc 7453 firmware · amd/epyc 74f3 firmware · amd/epyc 7443p firmware · amd/epyc 7443 firmware · amd/epyc 7413 firmware · amd/epyc 73f3 firmware · amd/epyc 7343 firmware · amd/epyc 7313p firmware · amd/epyc 7313 firmware · amd/epyc 72f3 firmware · amd/epyc 7773x firmware · +18 more
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.