First published: Tue May 10 2022(Updated: )
Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
AMD EPYC 7232p firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7232p firmware | ||
AMD EPYC 7302P Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7302P Firmware | ||
AMD EPYC 7402P Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7402P Firmware | ||
AMD EPYC 7502P Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7502P Firmware | ||
AMD EPYC 7702 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7702P | ||
AMD EPYC 7252 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7252 Firmware | ||
AMD EPYC 7262 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7262 Firmware | ||
AMD EPYC 7272 firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7272 firmware | ||
AMD EPYC 7282 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7282 Firmware | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7302 Firmware | ||
AMD EPYC Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7352 firmware | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7402 Firmware | ||
AMD EPYC 7452 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC Server | ||
AMD EPYC 7502 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7502 firmware | ||
AMD EPYC 7532 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7532 Firmware | ||
AMD EPYC 7542 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC Server | ||
AMD EPYC 7552 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7552 Firmware | ||
AMD EPYC 7642 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7642 Firmware | ||
AMD EPYC 7662 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7662 Firmware | ||
AMD EPYC 7702p firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC Server | ||
AMD EPYC 7742 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC Server | ||
AMD EPYC 7F32 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7F32 Firmware | ||
AMD EPYC 7F52 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7F52 Firmware | ||
AMD EPYC 7F72 | <romepi-sp3_1.0.0.d | |
AMD EPYC 7F72 Firmware | ||
AMD EPYC 7313P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7313P Firmware | ||
AMD EPYC 7443P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7443P Firmware | ||
AMD EPYC 7543P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7543P Firmware | ||
AMD EPYC 7713P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7713P Firmware | ||
AMD EPYC 7773X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7773X Firmware | ||
AMD EPYC 7763 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7763 Firmware | ||
AMD EPYC 7713P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7713 Firmware | ||
AMD EPYC 7663 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7663 Firmware | ||
AMD EPYC 7643P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7643 Firmware | ||
AMD EPYC 7573X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7573X Firmware | ||
AMD EPYC 75F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 75F3 Firmware | ||
AMD EPYC 7513 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7513 Firmware | ||
AMD EPYC 7473X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7473X Firmware | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC Server | ||
AMD EPYC 74F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 74F3 Firmware | ||
AMD EPYC 7413 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7413 Firmware | ||
AMD EPYC 73F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 73F3 Firmware | ||
AMD EPYC 7373X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7373X Firmware | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7343 Firmware | ||
AMD EPYC 72F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 72F3 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26364 is categorized as a critical vulnerability due to its potential to cause a denial of service through insufficient bounds checking.
To mitigate CVE-2021-26364, users should update the affected AMD EPYC firmware to the latest version available, specifically versions later than romepi-sp3_1.0.0.d or milanpi-sp3_1.0.0.7.
CVE-2021-26364 affects multiple models of AMD EPYC processors with specific firmware versions.
The main risk with CVE-2021-26364 is the potential for denial of service, which could disrupt system availability.
As of now, there is no public knowledge of an active exploit for CVE-2021-26364, but the vulnerability poses a significant risk.