SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26365

Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.

HIGH 8.2EPSS 0.57%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.

CVSS 3.1
8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
EPSS
0.57% probability · 45th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
amd/ryzen 5 2400g firmware · amd/ryzen 5 2400ge firmware · amd/ryzen 3 2200ge firmware · amd/ryzen 3 2200g firmware · amd/ryzen 3 pro 2100ge firmware · amd/ryzen 9 5900x firmware · amd/ryzen 9 5950x firmware · amd/ryzen 9 5900 firmware · amd/ryzen 7 5800 firmware · amd/ryzen 7 5800x firmware · amd/ryzen 7 5800x3d firmware · amd/ryzen 7 5700x firmware · amd/ryzen 5 5600 firmware · amd/ryzen 5 5600x firmware · amd/ryzen 5 5500 firmware · amd/ryzen 3 3200u firmware · amd/ryzen 3 3250c firmware · amd/ryzen 3 3250u firmware · amd/amd 3015e firmware · amd/amd 3015ce firmware · +34 more
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.