CVE-2021-26344: High severity amd epyc 7203 firmware vulnerability
An out of bounds memory write when processing the AMD PSP1 Configuration Block (APCB) could allow an attacker with access the ability to modify the BIOS image, and the ability to sign the resulting image, to potentially modify the APCB block resulting in arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26344?
CVE-2021-26344 has a high severity rating due to potential arbitrary code execution.
How do I fix CVE-2021-26344?
To fix CVE-2021-26344, ensure that you update the affected AMD EPYC firmware to a version higher than milanpi_1.0.0.5.
What systems are affected by CVE-2021-26344?
CVE-2021-26344 affects several AMD EPYC firmware versions, specifically versions before milanpi_1.0.0.5.
What kind of exploitation is possible with CVE-2021-26344?
Exploitation of CVE-2021-26344 could allow an attacker with access to modify BIOS images and execute arbitrary code.
Is it safe to continue using systems with CVE-2021-26344?
It is not safe to continue using affected systems without applying the firmware updates, as they are vulnerable to exploitation.