CVE-2021-26393
published 2022-11-09CVE-2021-26393: Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to…
PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.25%
15.9th percentile
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| amd | amd_radeon_rx_5000_series_pro_w5000_series | >= AMD Radeon Pro Software Enterprise < 22.Q2 | 22.Q2 |
| amd | amd_radeon_rx_5000_series_pro_w5000_series | >= AMD Radeon Software < 22.5.2 | 22.5.2 |
| amd | amd_radeon_rx_5000_series_pro_w5000_series | >= Enterprise Driver < 22.10.20 | 22.10.20 |
| amd | amd_radeon_rx_6000_series_pro_w6000_series | >= AMD Radeon Pro Software Enterprise < 22.Q2 | 22.Q2 |
| amd | amd_radeon_rx_6000_series_pro_w6000_series | >= AMD Radeon Software < 22.5.2 | 22.5.2 |
| amd | amd_radeon_rx_6000_series_pro_w6000_series | >= Enterprise Driver < 22.10.20 | 22.10.20 |
| amd | amd_ryzen_embedded_r1000 | — | — |
| amd | amd_ryzen_embedded_r2000 | — | — |
| amd | amd_ryzen_embedded_v1000 | — | — |
| amd | amd_ryzen_embedded_v2000 | — | — |
| amd | enterprise_driver | < 22.10.20 | 22.10.20 |
| amd | radeon_pro_software | < 22.q2 | 22.q2 |
| amd | radeon_software | < 22.5.2 | 22.5.2 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p326-98p9-wprv: Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges
ghsa_unreviewed·2022-11-10
CVE-2021-26393 [MEDIUM] CWE-401 GHSA-p326-98p9-wprv: Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.
Red Hat
hw: amd: Insufficient memory cleanup in ASP Trusted Execution Environment (TEE) may poison process contents
vendor_redhat·2022-11-08·CVSS 5.5
CVE-2021-26393 [MEDIUM] hw: amd: Insufficient memory cleanup in ASP Trusted Execution Environment (TEE) may poison process contents
hw: amd: Insufficient memory cleanup in ASP Trusted Execution Environment (TEE) may poison process contents
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.
A flaw was found in hw. Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker-controlled data, resulting in a loss of confidentiality.
Mitigation: Please contact AMD for more updates
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-11-09
Published