CVE-2021-26361: Medium severity AMD Radeon Software vulnerability
A malicious or compromised User Application (UApp) or AGESA Boot Loader (ABL) could be used by an attacker to exfiltrate arbitrary memory from the ASP stage 2 bootloader potentially leading to information disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26361?
CVE-2021-26361 has a medium severity level due to potential information disclosure by exfiltrating arbitrary memory from the bootloader.
How do I fix CVE-2021-26361?
To fix CVE-2021-26361, update the affected AMD firmware and software to the latest version provided by AMD.
Which systems are affected by CVE-2021-26361?
CVE-2021-26361 affects specific versions of AMD firmware, including those for Ryzen and Athlon processors, as detailed in the vulnerability report.
What types of attacks can exploit CVE-2021-26361?
CVE-2021-26361 can be exploited by an attacker via a malicious User Application or compromised AGESA Boot Loader.
What could be the impact of CVE-2021-26361?
The impact of CVE-2021-26361 includes the potential for unauthorized access to sensitive memory data, leading to information disclosure.