SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-26388

Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.

MEDIUM 5.5EPSS 0.22%

Does this matter?

Lower severity and a low EPSS score (0.22%). Track it; it rarely justifies an emergency change on its own.

Description

Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.

CVSS 3.1
5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS
0.22% probability · 12th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
amd/epyc 7232p firmware · amd/epyc 7302p firmware · amd/epyc 7402p firmware · amd/epyc 7502p firmware · amd/epyc 7702p firmware · amd/epyc 7252 firmware · amd/epyc 7262 firmware · amd/epyc 7272 firmware · amd/epyc 7282 firmware · amd/epyc 7302 firmware · amd/epyc 7352 firmware · amd/epyc 7402 firmware · amd/epyc 7452 firmware · amd/epyc 7502 firmware · amd/epyc 7532 firmware · amd/epyc 7542 firmware · amd/epyc 7552 firmware · amd/epyc 7642 firmware · amd/epyc 7662 firmware · amd/epyc 7702 firmware · +40 more
Source
psirt@amd.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.