CVE-2021-26338: High severity amd epyc 7f72 vulnerability
Improper access controls in System Management Unit (SMU) may allow for an attacker to override performance control tables located in DRAM resulting in a potential lack of system resources.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26338?
CVE-2021-26338 has a medium severity rating due to improper access controls that may lead to system resource issues.
How do I fix CVE-2021-26338?
To fix CVE-2021-26338, update your AMD EPYC firmware to the latest version that mitigates this vulnerability.
Which systems are affected by CVE-2021-26338?
CVE-2021-26338 affects certain versions of AMD EPYC firmware including 7f72, 7f52, 7f32, and others up to version romepi-sp3_1.0.0.c.
What impact does CVE-2021-26338 have on systems?
Exploitation of CVE-2021-26338 may allow an attacker to override performance control tables in DRAM, potentially compromising system performance.
Is CVE-2021-26338 exploitable remotely?
CVE-2021-26338 requires local access to the affected systems, limiting the scope of potential remote exploitation.