VulnerabilityModified
CVE-2021-46778
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT).
MEDIUM 5.6EPSS 0.23%
Does this matter?
Lower severity and a low EPSS score (0.23%). Track it; it rarely justifies an emergency change on its own.
Description
Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.
- CVSS 3.1
- 5.6 MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS
- 0.23% probability · 14th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-203
- Affected
- amd/athlon 3050ge firmware · amd/athlon 3150g firmware · amd/athlon 3150ge firmware · amd/epyc 7001 firmware · amd/epyc 7002 firmware · amd/epyc 7003 firmware · amd/epyc 7232p firmware · amd/epyc 7251 firmware · amd/epyc 7252 firmware · amd/epyc 7261 firmware · amd/epyc 7262 firmware · amd/epyc 7272 firmware · amd/epyc 7281 firmware · amd/epyc 7282 firmware · amd/epyc 72f3 firmware · amd/epyc 7301 firmware · amd/epyc 7302 firmware · amd/epyc 7302p firmware · amd/epyc 7313 firmware · amd/epyc 7313p firmware · +40 more
- Source
- psirt@amd.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.