CVE-2021-26340: High severity amd epyc server firmware vulnerability
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26340?
CVE-2021-26340 has a CVSS score that indicates a high severity due to the potential for privilege escalation and unexpected behavior in vulnerable AMD EPYC firmware.
How do I fix CVE-2021-26340?
To remediate CVE-2021-26340, users should update their AMD EPYC firmware to the latest version provided by the manufacturer.
Which systems are affected by CVE-2021-26340?
CVE-2021-26340 affects various AMD EPYC series firmware versions including 7001, 7232p, 7251, and others listed in the vulnerability documentation.
What types of attacks can exploit CVE-2021-26340?
CVE-2021-26340 can be exploited by an unprivileged attacker process within an SEV/SEV-ES guest VM, potentially allowing for privilege escalation.
Is my AMD EPYC system vulnerable to CVE-2021-26340?
To determine vulnerability to CVE-2021-26340, check your firmware version against the list of affected versions in the advisory from AMD.