First published: Wed May 11 2022(Updated: )
Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
AMD EPYC 7763 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7763 Firmware | ||
AMD EPYC 7713P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7713P Firmware | ||
AMD EPYC 7713P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7713 | ||
AMD EPYC 7663 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7663 Firmware | ||
AMD EPYC 7643 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7643 | ||
AMD EPYC 75F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 75F3 | ||
AMD EPYC 7543P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7543P Firmware | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7543 Firmware | ||
AMD EPYC 7513 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7513 | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7453 | ||
AMD EPYC 74F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 74F3 | ||
AMD EPYC 7443P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7443P | ||
AMD EPYC 7443 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7443 | ||
AMD EPYC 7413 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7413 Firmware | ||
AMD EPYC 73F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 73F3 | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7343 | ||
AMD EPYC 7313P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7313P | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7313P | ||
AMD EPYC 72F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 72F3 Firmware | ||
AMD EPYC 7773X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7773X | ||
AMD EPYC 7473X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7473X | ||
AMD EPYC 7573X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7573X | ||
AMD EPYC 7373X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7373X | ||
AMD EPYC 7002 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7002 | ||
AMD EPYC 7232p firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7232p firmware | ||
AMD EPYC 7252 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7252 Firmware | ||
AMD EPYC 7262 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7262 Firmware | ||
AMD EPYC 7272 firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7272 firmware | ||
AMD EPYC 7282 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7282 | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7302P | ||
AMD EPYC 7302P Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7302P | ||
AMD EPYC 7352 firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7352 | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7402 | ||
AMD EPYC 7402P Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7402P | ||
AMD EPYC 7452 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7452 | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7502 | ||
AMD EPYC 7502P Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7502P | ||
AMD EPYC 7532 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7532 | ||
AMD EPYC 7542 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7542 | ||
AMD EPYC 7552 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC Embedded 7552 | ||
AMD EPYC 7642 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7642 Firmware | ||
AMD EPYC 7662 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7662 | ||
AMD EPYC 7702 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7702 | ||
AMD EPYC 7702 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7702p | ||
AMD EPYC 7742 firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7742 firmware | ||
AMD EPYC 7F32 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7F32 Firmware | ||
AMD EPYC 7H12 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7H12 | ||
AMD EPYC 7F72 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7F72 | ||
AMD EPYC 7F52 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7F52 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26347 has a severity rating that indicates a potential denial of service risk due to integer overflow vulnerabilities.
To fix CVE-2021-26347, you should update the affected AMD EPYC firmware to a version above milanpi-sp3_1.0.0.7.
CVE-2021-26347 affects several AMD EPYC firmware versions, primarily those prior to milanpi-sp3_1.0.0.7.
The potential impacts of CVE-2021-26347 include system instability and possible service interruptions due to the integer overflow vulnerability.
Currently, the best workaround for CVE-2021-26347 is to ensure that all affected AMD EPYC systems are updated to the latest firmware version.