CVE-2021-26346
Severity
5.5MEDIUM
EPSS
0.1%
top 83.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 11
Description
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6
Affected Packages1 packages
🔴Vulnerability Details
2GHSA▶
GHSA-pj35-9jc4-v6rm: Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 dire↗2023-01-11
CVEList▶
CVE-2021-26346: Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 dire↗2023-01-10
📋Vendor Advisories
1Red Hat▶
hw: amd: integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service↗2023-01-10