CVE-2021-26329Improper Handling of Length Parameter Inconsistency in AMD 1ST GEN AMD Epyc

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 68.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 16
Latest updateMay 24

Description

AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resources.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages60 packages

CVEListV5amd/1st_gen_amd_epycunspecifiedNaplesPI-SP3_1.0.0.G
CVEListV5amd/2nd_gen_amd_epycunspecifiedRomePI-SP3_1.0.0.C
CVEListV5amd/3rd_gen_amd_epycunspecifiedMilanPI-SP3_1.0.0.4
NVDamd/epyc_7251_firmware< naplespi-sp3_1.0.0.g
NVDamd/epyc_7252_firmware< romepi-sp3_1.0.0.c

🔴Vulnerability Details

2
GHSA
GHSA-mr99-xfwj-whrq: AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resourc2022-05-24
CVEList
CVE-2021-26329: AMD System Management Unit (SMU) may experience an integer overflow when an invalid length is provided which may result in a potential loss of resourc2021-11-16
CVE-2021-26329 — AMD 1ST GEN AMD Epyc vulnerability | cvebase