CVE-2021-46748Improper Restriction of Operations within the Bounds of a Memory Buffer in AMD Radeon Software

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 76.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 14

Description

Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a TA (Trusted Application) resulting in a potential denial of service.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages6 packages

🔴Vulnerability Details

2
CVEList
CVE-2021-46748: Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a T2023-11-14
GHSA
GHSA-p483-8797-gq74: Insufficient bounds checking in the ASP (AMD Secure Processor) may allow an attacker to access memory outside the bounds of what is permissible to a T2023-11-14
CVE-2021-46748 — AMD Radeon Software vulnerability | cvebase