CVE-2021-26328: Medium severity amd epyc 7003 firmware vulnerability
Failure to verify the mode of CPU execution at the time of SNPINIT may lead to a potential loss of memory integrity for SNP guests.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-26328?
CVE-2021-26328 is a vulnerability that occurs when the mode of CPU execution is not properly verified during SNP_INIT, leading to a potential loss of memory integrity for SNP guests.
Which software versions are affected by CVE-2021-26328?
The affected software versions include AMD Epyc 7003 Firmware (up to exclusive version milanpi_1.0.0.8) and AMD Epyc 72f3, 7313, 7343, 7373x, 73f3, 7413, 7443, 7443p, 7453, 74f3, 7513, 7543, 7543p, 7573x, 75f3, 7643, 7663, 7713, 7713p, 7743, 7763, and 7773x Firmware (up to exclusive version milanpi_1.0.0.8).
What is the severity of CVE-2021-26328?
CVE-2021-26328 has a severity rating of 4.4, which is considered medium.
How does CVE-2021-26328 impact system security?
CVE-2021-26328 may lead to a potential loss of memory integrity for SNP guests, which can potentially impact system security.
How can I mitigate the vulnerability CVE-2021-26328?
To mitigate CVE-2021-26328, it is recommended to update the affected software versions to a fixed version provided by the vendor.