CVE-2021-26352Improper Restriction of Operations within the Bounds of a Memory Buffer in AMD Athlon Series

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 68.11%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 10
Latest updateMay 11

Description

Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could result in denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5amd/ryzen_seriesvarious
CVEListV5amd/athlon_seriesvarious

🔴Vulnerability Details

2
GHSA
GHSA-x9rp-5q33-qx3p: Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could re2022-05-11
CVEList
CVE-2021-26352: Insufficient bound checks in System Management Unit (SMU) PCIe Hot Plug table may result in access/updates from/to invalid address space that could re2022-05-10
CVE-2021-26352 — AMD Athlon Series vulnerability | cvebase