CVE-2021-26342: Low severity AMD Epyc 7763 Firmware vulnerability
In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV-SNP guest VMs are not impacted by this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26342?
CVE-2021-26342 has been classified with a severity level of high due to its potential to allow stale TLB translations in SEV guest VMs.
How do I fix CVE-2021-26342?
To mitigate CVE-2021-26342, users should update to the latest firmware, specifically version milanpi-sp3_1.0.0.7 or newer for affected AMD EPYC platforms.
Which AMD products are affected by CVE-2021-26342?
CVE-2021-26342 impacts several AMD EPYC processor firmware versions up to milanpi-sp3_1.0.0.7.
Can CVE-2021-26342 be exploited remotely?
Typically, CVE-2021-26342 requires local access to the vulnerable SEV guest environment, limiting its remote exploitability.
What are the potential consequences of exploiting CVE-2021-26342?
Exploitation of CVE-2021-26342 could lead to unauthorized access to sensitive information through stale data in the Translation Lookaside Buffer.