CVE-2021-26355

Severity
5.5MEDIUM
EPSS
0.1%
top 83.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 11

Description

Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages25 packages

NVDamd/epyc_7003_firmware< milanpi-sp3_1.0.0.7
NVDamd/epyc_72f3_firmware< milanpi-sp3_1.0.0.7
NVDamd/epyc_7313_firmware< milanpi-sp3_1.0.0.7
NVDamd/epyc_7343_firmware< milanpi-sp3_1.0.0.7
NVDamd/epyc_73f3_firmware< milanpi-sp3_1.0.0.7

🔴Vulnerability Details

2
GHSA
GHSA-p4w7-qphw-gm3c: Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potentia2023-01-11
CVEList
CVE-2021-26355: Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potentia2023-01-10
CVE-2021-26355 (MEDIUM CVSS 5.5) | Insufficient fencing and checks in | cvebase.io