VulnerabilityModified
CVE-2021-26378
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
MEDIUM 5.5EPSS 0.22%
Does this matter?
Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.
Description
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 0.22% probability · 12th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- amd/epyc 7232p firmware · amd/epyc 7302p firmware · amd/epyc 7402p firmware · amd/epyc 7502p firmware · amd/epyc 7702p firmware · amd/epyc 7252 firmware · amd/epyc 7262 firmware · amd/epyc 7272 firmware · amd/epyc 7282 firmware · amd/epyc 7302 firmware · amd/epyc 7352 firmware · amd/epyc 7402 firmware · amd/epyc 7452 firmware · amd/epyc 7502 firmware · amd/epyc 7532 firmware · amd/epyc 7542 firmware · amd/epyc 7552 firmware · amd/epyc 7642 firmware · amd/epyc 7662 firmware · amd/epyc 7702 firmware · +40 more
- Source
- psirt@amd.com
References
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1028Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1028Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.