CWE
203 208
Advisory Published
Updated

CVE-2021-26314: AMD Speculative execution with Floating-Point Value Injection

First published: Wed Jun 09 2021(Updated: )

Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.

Credit: psirt@amd.com

Affected SoftwareAffected VersionHow to fix
Xen Xen
Amd Ryzen 5 5600x
Amd Ryzen 7 2700x
Amd Ryzen Threadripper 2990wx
Arm Cortex-a72
Broadcom Bcm2711
Intel Core I7-10700k
Intel Core I7-7700k
Intel Core I9-9900k
Intel Xeon Silver 4214
Fedoraproject Fedora=33
Fedoraproject Fedora=34

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is CVE-2021-26314?

    CVE-2021-26314 refers to a potential floating point value injection vulnerability found in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results.

  • Which software products are affected by CVE-2021-26314?

    Xen Xen, Arm Cortex-a72, Broadcom Bcm2711, Intel Core I7-10700k, Intel Core I7-7700k, Intel Core I9-9900k, Intel Xeon Silver 4214, and Fedoraproject Fedora versions 33 and 34 are affected by CVE-2021-26314.

  • What is the severity rating of CVE-2021-26314?

    CVE-2021-26314 has a severity rating of 5.5 (Medium).

  • How can I mitigate CVE-2021-26314?

    Apply the necessary software patches and updates provided by the respective software vendors to mitigate CVE-2021-26314.

  • Where can I find more information about CVE-2021-26314?

    You can find more information about CVE-2021-26314 at the following references: [Reference 1](http://www.openwall.com/lists/oss-security/2021/06/09/2), [Reference 2](http://www.openwall.com/lists/oss-security/2021/06/10/1), [Reference 3](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/H36U6CNREC436W6GYO7QUMJIVEA35SCV/).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203