CVE-2021-26313Observable Timing Discrepancy in AMD ALL Supported Processors

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 76.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 24

Description

Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages3 packages

CVEListV5amd/all_supported_processorsunspecifiedundefined
debiandebian/xen< xen 4.14.2+25-gb6a8c4f72d-1 (bookworm)
Debianxen/xen< 4.14.2+25-gb6a8c4f72d-1+3

Also affects: Debian Linux 10.0

🔴Vulnerability Details

2
GHSA
GHSA-vj56-jg6h-3gpr: Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution2022-05-24
OSV
CVE-2021-26313: Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution2021-06-09

📋Vendor Advisories

1
Debian
CVE-2021-26313: xen - Potential speculative code store bypass in all supported CPU products, in conjun...2021