First published: Tue Nov 09 2021(Updated: )
Failure to validate VM_HSAVE_PA during SNP_INIT may result in a loss of memory integrity.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
AMD EPYC 7232p firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7232p firmware | ||
AMD EPYC 7763 Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7763 Firmware | ||
AMD EPYC 7713P Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7713P Firmware | ||
AMD EPYC 7713P Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7713 Firmware | ||
AMD EPYC 7663 Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7663 Firmware | ||
AMD EPYC 7643P Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7643 Firmware | ||
AMD EPYC 75F3 Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 75F3 Firmware | ||
AMD EPYC 7543P Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7543P Firmware | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7543 Firmware | ||
AMD EPYC 7513 Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7513 Firmware | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7453 | ||
AMD EPYC 74F3 Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 74F3 Firmware | ||
AMD EPYC 7443P Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7443P Firmware | ||
AMD EPYC 7443P Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7443P | ||
AMD EPYC 7413 Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7413 Firmware | ||
AMD EPYC 73F3 Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 73F3 Firmware | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7343 Firmware | ||
AMD EPYC 7313P Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7313P Firmware | ||
AMD EPYC 7313P Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 7313 Firmware | ||
AMD EPYC 72F3 Firmware | <milanpi-sp3_1.0.0.4 | |
AMD EPYC 72F3 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26326 has been classified as a high-severity vulnerability due to its potential impact on memory integrity.
To fix CVE-2021-26326, you should update your AMD EPYC firmware to the latest version specified in the AMD security bulletin.
CVE-2021-26326 primarily affects various versions of AMD EPYC firmware up to romepi-sp3_1.0.0.c.
Yes, CVE-2021-26326 may allow an attacker to exploit vulnerable systems remotely due to improper validation during initialization.
Currently, the best approach for mitigating CVE-2021-26326 is to apply the firmware updates as there are no effective workarounds provided.