VulnerabilityModified
CVE-2021-26363
A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.
MEDIUM 4.4EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Affected
- amd/radeon software · amd/ryzen 3 3100 firmware · amd/ryzen 3 3300g firmware · amd/ryzen 3 3300x firmware · amd/ryzen 3 5400u firmware · amd/ryzen 9 5900hs firmware · amd/ryzen 9 5900hx firmware · amd/ryzen 9 5980hs firmware · amd/ryzen 9 5980hx firmware · amd/ryzen 3 5125c firmware · amd/ryzen 3 5425c firmware · amd/ryzen 7 3700x firmware · amd/ryzen 9 3900x firmware · amd/ryzen 9 3950x firmware · amd/ryzen 7 3800x firmware · amd/ryzen 3 5425u firmware · amd/ryzen 5 3400g firmware · amd/ryzen 7 5800h firmware · amd/ryzen 7 5800hs firmware · amd/ryzen 7 5800u firmware · +14 more
- Source
- psirt@amd.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.