CVE-2021-26375

3 documents3 sources
Severity
5.5MEDIUM
EPSS
0.1%
top 69.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateMay 12

Description

Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages86 packages

NVDamd/epyc_7252_firmware< romepi-sp3_1.0.0.d
NVDamd/epyc_7262_firmware< romepi-sp3_1.0.0.d
NVDamd/epyc_7272_firmware< romepi-sp3_1.0.0.d
NVDamd/epyc_7282_firmware< romepi-sp3_1.0.0.d
NVDamd/epyc_72f3_firmware< milanpi-sp3_1.0.0.7

🔴Vulnerability Details

2
GHSA
GHSA-xqhm-4h4h-vgmh: Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that co2022-05-12
CVEList
CVE-2021-26375: Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that co2022-05-11
CVE-2021-26375 (MEDIUM CVSS 5.5) | Insufficient General Purpose IO (GP | cvebase.io