cbcvebase.
CVE-2021-26393
published 2022-11-09

CVE-2021-26393: Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to…

PriorityP425medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.25%
15.9th percentile
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.

Affected

13 ranges
VendorProductVersion rangeFixed in
amdamd_radeon_rx_5000_series_pro_w5000_series>= AMD Radeon Pro Software Enterprise < 22.Q222.Q2
amdamd_radeon_rx_5000_series_pro_w5000_series>= AMD Radeon Software < 22.5.222.5.2
amdamd_radeon_rx_5000_series_pro_w5000_series>= Enterprise Driver < 22.10.2022.10.20
amdamd_radeon_rx_6000_series_pro_w6000_series>= AMD Radeon Pro Software Enterprise < 22.Q222.Q2
amdamd_radeon_rx_6000_series_pro_w6000_series>= AMD Radeon Software < 22.5.222.5.2
amdamd_radeon_rx_6000_series_pro_w6000_series>= Enterprise Driver < 22.10.2022.10.20
amdamd_ryzen_embedded_r1000
amdamd_ryzen_embedded_r2000
amdamd_ryzen_embedded_v1000
amdamd_ryzen_embedded_v2000
amdenterprise_driver< 22.10.2022.10.20
amdradeon_pro_software< 22.q222.q2
amdradeon_software< 22.5.222.5.2

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.