cbcvebase.
CVE-2021-26344
published 2024-08-13

CVE-2021-26344: An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image…

high8.2CVSS 3.1
AVLACLPRHUINSCCHIHAH
An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.

Affected

69 ranges· showing 25
VendorProductVersion rangeFixed in
amdamd_athlon_3000_series_desktop_processors_with_radeon_graphics
amdamd_athlon_3000_series_mobile_processors_with_radeon_graphics
amdamd_epyc_7001_series_processors
amdamd_epyc_embedded_3000_series_processors
amdamd_ryzen_3000_series_desktop_processors
amdamd_ryzen_3000_series_mobile_processors_with_radeon_graphics
amdamd_ryzen_4000_series_desktop_processors_with_radeon_graphics
amdamd_ryzen_4000_series_mobile_processors_with_radeon_graphics
amdamd_ryzen_5000_series_mobile_processors_with_radeon_graphics
amdamd_ryzen_embedded_5000_series_processors
amdamd_ryzen_embedded_r1000_series_processors
amdamd_ryzen_embedded_r2000_series_processors
amdamd_ryzen_embedded_v1000_series_processors
amdamd_ryzen_embedded_v2000_series_processors
amdamd_ryzen_threadripper_3000_series_processors
amdepyc_7203_firmware< milanpi_1.0.0.5milanpi_1.0.0.5
amdepyc_7203p_firmware< milanpi_1.0.0.5milanpi_1.0.0.5
amdepyc_7232p_firmware< romepi_1.0.0.cromepi_1.0.0.c
amdepyc_7252_firmware< romepi_1.0.0.cromepi_1.0.0.c
amdepyc_7262_firmware< romepi_1.0.0.cromepi_1.0.0.c
amdepyc_7272_firmware< romepi_1.0.0.cromepi_1.0.0.c
amdepyc_7282_firmware< romepi_1.0.0.cromepi_1.0.0.c
amdepyc_72f3_firmware< milanpi_1.0.0.5milanpi_1.0.0.5
amdepyc_7302_firmware< romepi_1.0.0.cromepi_1.0.0.c
amdepyc_7302p_firmware< romepi_1.0.0.cromepi_1.0.0.c