CVE-2021-26382: Medium severity amd ryzen 7 5700g firmware vulnerability
An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for authenticating an ACP firmware image, potentially resulting in a denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26382?
CVE-2021-26382 has a moderate severity level, allowing attackers with root privileges to load unauthorized firmware, potentially causing a denial of service.
How do I fix CVE-2021-26382?
To fix CVE-2021-26382, users should update to the latest firmware version from AMD that addresses this vulnerability.
Who is affected by CVE-2021-26382?
CVE-2021-26382 affects specific AMD Ryzen firmware versions, particularly those below comboam4_v2_pi_1.2.0.6c and cezannepi-fp6_1.0.0.9.
What are the potential impacts of CVE-2021-26382?
The potential impacts of CVE-2021-26382 include unauthorized firmware loading and subsequent denial of service due to firmware manipulation.
Is there any workaround for CVE-2021-26382?
Currently, there are no documented workarounds for CVE-2021-26382; updating firmware is the recommended solution.