CVE-2021-26350

CWE-3673 documents3 sources
Severity
4.7MEDIUM
EPSS
0.0%
top 88.25%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateMay 12

Description

A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.0 | Impact: 3.6

Affected Packages45 packages

NVDamd/epyc_7252_firmware< romepi-sp3_1.0.0.d
NVDamd/epyc_7262_firmware< romepi-sp3_1.0.0.d
NVDamd/epyc_7272_firmware< romepi-sp3_1.0.0.d
NVDamd/epyc_7282_firmware< romepi-sp3_1.0.0.d
NVDamd/epyc_72f3_firmware< milanpi-sp3_1.0.0.7

🔴Vulnerability Details

2
GHSA
GHSA-x724-6q24-6qf9: A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potentia2022-05-12
CVEList
CVE-2021-26350: A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potentia2022-05-11