CWE
20
Advisory Published
Updated

CVE-2021-26351: Input Validation

First published: Thu May 12 2022(Updated: )

Insufficient DRAM address validation in System Management Unit (SMU) may result in a DMA (Direct Memory Access) read/write from/to invalid DRAM address that could result in denial of service.

Credit: psirt@amd.com

Affected SoftwareAffected VersionHow to fix
AMD Ryzen 3100 Firmware
AMD Ryzen 3 3100 Firmware
AMD Ryzen 3 3300G Firmware
AMD Ryzen 3 3300G Firmware
AMD Ryzen 3 3300X Firmware
AMD Ryzen 3 3300X Firmware
AMD Ryzen 3 5125C Firmware
AMD Ryzen 3 5125C Firmware
AMD Ryzen 3 5400U Firmware
AMD Ryzen 3 5400U Firmware
AMD Ryzen 3 5425C Firmware
AMD Ryzen 3 5425C Firmware
AMD Ryzen 3 5425U
AMD Ryzen 3 5425U Firmware
AMD Ryzen 5 Pro 3400G Firmware
AMD Ryzen 5 3400G Firmware
AMD Ryzen 5 3450G Firmware
AMD Ryzen 5 3450G Firmware
AMD Ryzen 5 3600 firmware
AMD Ryzen 5 3600 firmware
AMD Ryzen 5 3600X Firmware
AMD Ryzen 5 3600X Firmware
AMD Ryzen 5 5560U Firmware
AMD Ryzen 5 5560U Firmware
AMD Ryzen 5 5600H Firmware
AMD Ryzen 5 5600H Firmware
AMD Ryzen 5 5600HS Firmware
AMD Ryzen 5 5600HS Firmware
AMD Ryzen 5 5600U Firmware
AMD Ryzen 5 5600U Firmware
AMD Ryzen 5 5600X
AMD Ryzen 5 5600X Firmware
AMD Ryzen 5 5625C Firmware
AMD Ryzen 5 5625C Firmware
AMD Ryzen 5 5625U Firmware
AMD Ryzen 5 5625U Firmware
AMD Ryzen 5 5700G Firmware
AMD Ryzen 5 5700G
AMD Ryzen 5 5700GE Firmware
AMD Ryzen 5 5700GE
AMD Ryzen 7 3700X Firmware
AMD Ryzen 7 3700XT
AMD Ryzen 7 3800XT Firmware
AMD Ryzen 7 3800X Firmware
AMD Ryzen 7 5800H Firmware
AMD Ryzen 7 5800H Firmware
AMD Ryzen 7 5800HS Firmware
AMD Ryzen 7 5800HS Firmware
AMD Ryzen 7 5800U Firmware
AMD Ryzen 7 5800U Firmware
AMD Ryzen 7 5825C Firmware
AMD Ryzen 7 5825C Firmware
AMD Ryzen 7 5825U Firmware
AMD Ryzen 7 5825U Firmware
AMD Ryzen 9 3900X
AMD Ryzen 9 3900X
AMD Ryzen 9 3950XT firmware
AMD Ryzen 9 3950XT
AMD Ryzen 9 5900HS Firmware
AMD Ryzen 9 5900HS Firmware
AMD Ryzen 9 5900HX Firmware
AMD Ryzen 9 5900HX Firmware
AMD Ryzen 9 5980HS Firmware
AMD Ryzen 9 5980HS Firmware
AMD Ryzen 9 5980HX
AMD Ryzen 9 5980HX
AMD Ryzen Threadripper 2920X
AMD Ryzen Threadripper 2920X Firmware
AMD Ryzen Threadripper 2950X Firmware
AMD Ryzen Threadripper 2950X Firmware
AMD Ryzen Threadripper 2970WX Firmware
AMD Ryzen Threadripper 2970WX Firmware
AMD Ryzen Threadripper 2990WX
AMD Ryzen Threadripper 2990WX
AMD Ryzen Threadripper 3960X Firmware
AMD Ryzen Threadripper 3960X Firmware
AMD Ryzen Threadripper 3970X
AMD Ryzen Threadripper 3970X Firmware
AMD Ryzen Threadripper 3990X
AMD Ryzen Threadripper 3990X
AMD Ryzen Threadripper Pro
AMD Ryzen Threadripper Pro 3945WX Firmware
AMD Ryzen Threadripper Pro 3955WX Firmware
AMD Ryzen Threadripper Pro 3955WX Firmware
AMD Ryzen Threadripper Pro 3975WX Firmware
AMD Ryzen Threadripper Pro 3975WX Firmware
AMD Ryzen Threadripper Pro 3995WX Firmware
AMD Ryzen Threadripper Pro
AMD Ryzen Threadripper Pro 5945WX Firmware
AMD Ryzen Threadripper Pro 5945WX Firmware
AMD Ryzen Threadripper Pro 5955WX Firmware
AMD Ryzen Threadripper Pro 5955WX Firmware
AMD Ryzen Threadripper Pro 5965WX Firmware
AMD Ryzen Threadripper Pro
AMD Ryzen Threadripper Pro 5975W Firmware
AMD Ryzen Threadripper Pro 5975W Firmware
AMD Ryzen Threadripper Pro 5995WX Firmware
AMD Ryzen Threadripper Pro 5995WX Firmware

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2021-26351?

    CVE-2021-26351 is classified as a medium severity vulnerability.

  • How do I fix CVE-2021-26351?

    To fix CVE-2021-26351, users should update the firmware of affected AMD Ryzen processors to the latest version provided by AMD.

  • What are the potential impacts of CVE-2021-26351?

    CVE-2021-26351 may allow unauthorized DMA read/write operations which can lead to denial of service.

  • Which AMD products are affected by CVE-2021-26351?

    CVE-2021-26351 impacts multiple AMD Ryzen processors including the Ryzen 3, Ryzen 5, Ryzen 7, and Ryzen 9 series.

  • Is there a known exploit for CVE-2021-26351?

    As of now, there is no publicly known exploit for CVE-2021-26351.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203