CVE-2021-26313 — Observable Timing Discrepancy in AMD ALL Supported Processors
Severity
5.5MEDIUMNVD
EPSS
0.1%
top 76.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJun 9
Latest updateMay 24
Description
Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution of overwritten instructions, may cause an incorrect speculation and could result in data leakage.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6
Affected Packages3 packages
Also affects: Debian Linux 10.0
🔴Vulnerability Details
2GHSA▶
GHSA-vj56-jg6h-3gpr: Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution↗2022-05-24
OSV▶
CVE-2021-26313: Potential speculative code store bypass in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution↗2021-06-09
📋Vendor Advisories
1Debian▶
CVE-2021-26313: xen - Potential speculative code store bypass in all supported CPU products, in conjun...↗2021