CVE-2021-26346

CWE-190Integer Overflow4 documents4 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 83.19%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 11

Description

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages1 packages

CVEListV5amd/ryzen_5000_seriesvarious

🔴Vulnerability Details

2
GHSA
GHSA-pj35-9jc4-v6rm: Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 dire2023-01-11
CVEList
CVE-2021-26346: Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 dire2023-01-10

📋Vendor Advisories

1
Red Hat
hw: amd: integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service2023-01-10