CVE-2021-26347: Integer Overflow
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26347?
CVE-2021-26347 has a severity rating that indicates a potential denial of service risk due to integer overflow vulnerabilities.
How do I fix CVE-2021-26347?
To fix CVE-2021-26347, you should update the affected AMD EPYC firmware to a version above milanpi-sp3_1.0.0.7.
Which AMD products are affected by CVE-2021-26347?
CVE-2021-26347 affects several AMD EPYC firmware versions, primarily those prior to milanpi-sp3_1.0.0.7.
What are the potential impacts of CVE-2021-26347?
The potential impacts of CVE-2021-26347 include system instability and possible service interruptions due to the integer overflow vulnerability.
Is there a workaround for CVE-2021-26347?
Currently, the best workaround for CVE-2021-26347 is to ensure that all affected AMD EPYC systems are updated to the latest firmware version.