CVE-2021-26320: Medium severity AMD Epyc 7601 Firmware vulnerability
Insufficient validation of the AMD SEV Signing Key (ASK) in the SENDSTART command in the SEV Firmware may allow a local authenticated attacker to perform a denial of service of the PSP
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26320?
CVE-2021-26320 has a medium severity rating due to insufficient validation of the AMD SEV Signing Key which could lead to a denial of service.
How do I fix CVE-2021-26320?
To fix CVE-2021-26320, update the affected AMD Epyc firmware to the latest version available from the manufacturer.
Which AMD Epyc firmware versions are affected by CVE-2021-26320?
CVE-2021-26320 affects multiple versions of the AMD Epyc firmware prior to the patch marked in the security bulletin from AMD.
What could be the impact of CVE-2021-26320 if exploited?
If exploited, CVE-2021-26320 could allow local authenticated attackers to cause a denial of service affecting the Platform Security Processor (PSP).
Is there a workaround for CVE-2021-26320 while waiting for a patch?
Currently, the best approach for CVE-2021-26320 is to apply the firmware update, as there are no known workarounds that effectively mitigate the risk.