VulnerabilityModified
CVE-2021-26365
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.
HIGH 8.2EPSS 0.57%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.57%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.
- CVSS 3.1
- 8.2 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
- EPSS
- 0.57% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- amd/ryzen 5 2400g firmware · amd/ryzen 5 2400ge firmware · amd/ryzen 3 2200ge firmware · amd/ryzen 3 2200g firmware · amd/ryzen 3 pro 2100ge firmware · amd/ryzen 9 5900x firmware · amd/ryzen 9 5950x firmware · amd/ryzen 9 5900 firmware · amd/ryzen 7 5800 firmware · amd/ryzen 7 5800x firmware · amd/ryzen 7 5800x3d firmware · amd/ryzen 7 5700x firmware · amd/ryzen 5 5600 firmware · amd/ryzen 5 5600x firmware · amd/ryzen 5 5500 firmware · amd/ryzen 3 3200u firmware · amd/ryzen 3 3250c firmware · amd/ryzen 3 3250u firmware · amd/amd 3015e firmware · amd/amd 3015ce firmware · +34 more
- Source
- psirt@amd.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.