First published: Tue Nov 16 2021(Updated: )
Insufficient input validation in the SNP_GUEST_REQUEST command may lead to a potential data abort error and a denial of service.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
Amd Epyc 7232p Firmware | <romepi-sp3_1.0.0.c | |
Amd Epyc 7232p | ||
Amd Epyc 7763 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7763 | ||
Amd Epyc 7713p Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7713p | ||
Amd Epyc 7713 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7713 | ||
Amd Epyc 7663 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7663 | ||
Amd Epyc 7643 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7643 | ||
Amd Epyc 75f3 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 75f3 | ||
Amd Epyc 7543p Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7543p | ||
Amd Epyc 7543 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7543 | ||
Amd Epyc 7513 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7513 | ||
Amd Epyc 7453 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7453 | ||
Amd Epyc 74f3 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 74f3 | ||
Amd Epyc 7443p Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7443p | ||
Amd Epyc 7443 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7443 | ||
Amd Epyc 7413 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7413 | ||
Amd Epyc 73f3 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 73f3 | ||
Amd Epyc 7343 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7343 | ||
Amd Epyc 7313p Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7313p | ||
Amd Epyc 7313 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 7313 | ||
Amd Epyc 72f3 Firmware | <milanpi-sp3_1.0.0.4 | |
Amd Epyc 72f3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-26325.
The severity of CVE-2021-26325 is medium, with a severity value of 5.5.
The affected software includes AMD Epyc 7232p Firmware (up to version romepi-sp3_1.0.0.c), AMD Epyc 7763 Firmware (up to version milanpi-sp3_1.0.0.4), and others.
The potential impact of CVE-2021-26325 is a data abort error and a denial of service.
You can find more information about CVE-2021-26325 on the AMD Product Security Bulletin page at https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1021.