CVE-2021-26355: Medium severity amd epyc 7003 firmware vulnerability
Insufficient fencing and checks in System Management Unit (SMU) may result in access to invalid message port registers that could result in a potential denial-of-service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-26355.
What is the description of CVE-2021-26355?
CVE-2021-26355 is a vulnerability that involves insufficient fencing and checks in the System Management Unit (SMU), which may result in access to invalid message port registers and potential denial-of-service.
Which software versions are affected by CVE-2021-26355?
The affected software versions for CVE-2021-26355 are Amd Epyc 7003 Firmware up to but excluding milanpi-sp3_1.0.0.7 and Amd Epyc 72f3 Firmware up to but excluding milanpi-sp3_1.0.0.7.
What is the severity of CVE-2021-26355?
CVE-2021-26355 has a severity value of 5.5, which is classified as medium.
How can I fix CVE-2021-26355?
To fix CVE-2021-26355, it is recommended to apply the necessary updates or patches provided by AMD to the affected software versions.