CVE-2021-26314
published 2021-06-09CVE-2021-26314: Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.61%
45.1th percentile
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | all_supported_processors | >= unspecified < undefined | undefined |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-92cv-8jc7-jrpm: Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution
ghsa_unreviewed·2022-05-24
CVE-2021-26314 [MEDIUM] CWE-203 GHSA-92cv-8jc7-jrpm: Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
OSV
CVE-2021-26314: Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution
osv·2021-06-09·CVSS 5.5
CVE-2021-26314 [MEDIUM] CVE-2021-26314: Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.openwall.com/lists/oss-security/2021/06/09/2http://www.openwall.com/lists/oss-security/2021/06/10/1https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H36U6CNREC436W6GYO7QUMJIVEA35SCV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVA2NY26MMXOODUMYZN5DCU3FXMBMBOB/https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1003http://www.openwall.com/lists/oss-security/2021/06/09/2http://www.openwall.com/lists/oss-security/2021/06/10/1https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H36U6CNREC436W6GYO7QUMJIVEA35SCV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVA2NY26MMXOODUMYZN5DCU3FXMBMBOB/https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1003
2021-06-09
Published