VulnerabilityModified
CVE-2021-26364
Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service.
MEDIUM 5.5EPSS 0.21%
Does this matter?
Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.21% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- amd/epyc 7232p firmware · amd/epyc 7302p firmware · amd/epyc 7402p firmware · amd/epyc 7502p firmware · amd/epyc 7702p firmware · amd/epyc 7252 firmware · amd/epyc 7262 firmware · amd/epyc 7272 firmware · amd/epyc 7282 firmware · amd/epyc 7302 firmware · amd/epyc 7352 firmware · amd/epyc 7402 firmware · amd/epyc 7452 firmware · amd/epyc 7502 firmware · amd/epyc 7532 firmware · amd/epyc 7542 firmware · amd/epyc 7552 firmware · amd/epyc 7642 firmware · amd/epyc 7662 firmware · amd/epyc 7702 firmware · +24 more
- Source
- psirt@amd.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.