First published: Tue May 10 2022(Updated: )
Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
AMD EPYC 7232p firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7232p firmware | ||
AMD EPYC 7302P Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7302P | ||
AMD EPYC 7402P Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7402P | ||
AMD EPYC 7502P Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7502P | ||
AMD EPYC 7702 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7702p | ||
AMD EPYC 7252 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7252 Firmware | ||
AMD EPYC 7262 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7262 Firmware | ||
AMD EPYC 7272 firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7272 firmware | ||
AMD EPYC 7282 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7282 | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7302P | ||
AMD EPYC 7352 firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7352 | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7402 | ||
AMD EPYC 7452 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7452 | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7502 | ||
AMD EPYC 7532 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7532 | ||
AMD EPYC 7542 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7542 | ||
AMD EPYC 7552 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC Embedded 7552 | ||
AMD EPYC 7642 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7642 Firmware | ||
AMD EPYC 7662 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7662 | ||
AMD EPYC 7702 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7702 | ||
AMD EPYC 7742 firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7742 firmware | ||
AMD EPYC 7F32 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7F32 Firmware | ||
AMD EPYC 7F52 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7F52 | ||
AMD EPYC 7F72 Firmware | <romepi-sp3_1.0.0.d | |
AMD EPYC 7F72 | ||
AMD EPYC 7313P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7313P | ||
AMD EPYC 7443P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7443P | ||
AMD EPYC 7543P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7543P Firmware | ||
AMD EPYC 7713P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7713P Firmware | ||
AMD EPYC 7773X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7773X | ||
AMD EPYC 7763 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7763 Firmware | ||
AMD EPYC 7713P Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7713 | ||
AMD EPYC 7663 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7663 Firmware | ||
AMD EPYC 7643 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7643 | ||
AMD EPYC 7573X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7573X | ||
AMD EPYC 75F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 75F3 | ||
AMD EPYC 7513 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7513 | ||
AMD EPYC 7473X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7473X | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7453 | ||
AMD EPYC 74F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 74F3 | ||
AMD EPYC 7413 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7413 Firmware | ||
AMD EPYC 73F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 73F3 | ||
AMD EPYC 7373X Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7373X | ||
Amd Epyc Server Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 7343 | ||
AMD EPYC 72F3 Firmware | <milanpi-sp3_1.0.0.7 | |
AMD EPYC 72F3 Firmware | ||
AMD Ryzen 7 2700X | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 7 2700X | ||
AMD Ryzen 7 2700X | <comboam4pi_1.0.0.8 | |
AMD Ryzen 7 2700 Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 7 2700 Firmware | ||
AMD Ryzen 7 2700 Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 5 2600X | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 5 2600X | ||
AMD Ryzen 5 2600X | <comboam4pi_1.0.0.8 | |
AMD Ryzen 5 2700 firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 5 2700 | ||
AMD Ryzen 5 2700 firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 3 3100 Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 3 3100 Firmware | ||
AMD Ryzen 3 3100 Firmware | <comboam4_v2_pi_1.2.0.6c | |
amd ryzen 3 3300 | ||
AMD Ryzen 3 3300X Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 3 3300X Firmware | ||
AMD Ryzen 3 3300X Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 9 5950X | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 9 5950X | ||
AMD Ryzen 7 5800X3D Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 7 5800X3D | ||
AMD Ryzen 9 5900X Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 9 5900X | ||
AMD Ryzen 7 5800X Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 7 5800X | ||
AMD Ryzen 5 5600X Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 5 5600X Firmware | ||
AMD Ryzen 7 5700X Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 7 5700X Firmware | ||
AMD Ryzen 5 5600 Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 5 5600 | ||
AMD Ryzen 5 5500 firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 5 5500 firmware | ||
AMD Ryzen 7 5700G Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 7 5700G Firmware | ||
AMD Ryzen 5 5600G Firmware | <comboam4_v2_pi_1.2.0.6c | |
AMD Ryzen 5 5600GT Firmware | ||
AMD Ryzen Threadripper 2990WX | <summitpi-sp3r2_1.1.0.5 | |
AMD Ryzen Threadripper 2990WX | ||
AMD Ryzen Threadripper 2970WX Firmware | <summitpi-sp3r2_1.1.0.5 | |
AMD Ryzen Threadripper 2970WX Firmware | ||
AMD Ryzen Threadripper 2950X Firmware | <summitpi-sp3r2_1.1.0.5 | |
AMD Ryzen Threadripper 2950X Firmware | ||
AMD Ryzen Threadripper 2920X Firmware | <summitpi-sp3r2_1.1.0.5 | |
AMD Ryzen Threadripper 2920X Firmware | ||
AMD Ryzen Threadripper 3990X | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 3990X | ||
AMD Ryzen Threadripper 3970X Firmware | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 3970X Firmware | ||
AMD Ryzen Threadripper 3960X Firmware | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 3960X Firmware | ||
AMD Ryzen Threadripper 2990WX | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 2970WX Firmware | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 2950X Firmware | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 2920X Firmware | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 1950X Firmware | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 1950X Firmware | ||
AMD Ryzen Threadripper 1920X Firmware | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 1920X | ||
AMD Ryzen Threadripper 1900X Firmware | <castlepeakpi-sp3r3_1.0.0.7 | |
AMD Ryzen Threadripper 1900X Firmware | ||
AMD Ryzen Threadripper Pro 3945WX Firmware | <chagallwspi-swrx8_1.0.0.2 | |
AMD Ryzen Threadripper Pro 3945WX Firmware | ||
AMD Ryzen Threadripper Pro 3955WX Firmware | <chagallwspi-swrx8_1.0.0.2 | |
AMD Ryzen Threadripper Pro 3955WX | ||
AMD Ryzen Threadripper Pro 3975WX Firmware | <chagallwspi-swrx8_1.0.0.2 | |
AMD Ryzen Threadripper Pro 3975WX Firmware | ||
AMD Ryzen Threadripper Pro 3995WX Firmware | <chagallwspi-swrx8_1.0.0.2 | |
AMD Ryzen Threadripper Pro 3995WX | ||
AMD Ryzen Threadripper Pro 5945WX Firmware | <chagallwspi-swrx8_1.0.0.2 | |
AMD Ryzen Threadripper Pro 5945WX Firmware | ||
AMD Ryzen Threadripper Pro 5955WX Firmware | <chagallwspi-swrx8_1.0.0.2 | |
AMD Ryzen Threadripper Pro 5955WX Firmware | ||
AMD Ryzen Threadripper Pro 5965WX Firmware | <chagallwspi-swrx8_1.0.0.2 | |
AMD Ryzen Threadripper Pro 5965WX Firmware | ||
AMD Ryzen Threadripper Pro 5975WX Firmware | <chagallwspi-swrx8_1.0.0.2 | |
AMD Ryzen Threadripper PRO 5975WX | ||
AMD Ryzen Threadripper Pro 5995WX Firmware | <chagallwspi-swrx8_1.0.0.2 | |
AMD Ryzen Threadripper Pro 5995WX | ||
AMD Ryzen Threadripper Pro 3945WX Firmware | <castlepeakwspi-swrx8_1.0.0.9 | |
AMD Ryzen Threadripper Pro 3955WX Firmware | <castlepeakwspi-swrx8_1.0.0.9 | |
AMD Ryzen Threadripper Pro 3975WX Firmware | <castlepeakwspi-swrx8_1.0.0.9 | |
AMD Ryzen Threadripper Pro 3995WX Firmware | <castlepeakwspi-swrx8_1.0.0.9 | |
AMD Ryzen Threadripper Pro 5945WX Firmware | <castlepeakwspi-swrx8_1.0.0.9 | |
AMD Ryzen Threadripper Pro 5955WX Firmware | <castlepeakwspi-swrx8_1.0.0.9 | |
AMD Ryzen Threadripper Pro 5965WX Firmware | <castlepeakwspi-swrx8_1.0.0.9 | |
AMD Ryzen Threadripper Pro 5975WX Firmware | <castlepeakwspi-swrx8_1.0.0.9 | |
AMD Ryzen Threadripper Pro 5995WX Firmware | <castlepeakwspi-swrx8_1.0.0.9 | |
AMD Ryzen 3 2200U Firmware | <raven-fp5-am4_1.1.0.e | |
AMD Ryzen 3 2200U Firmware | ||
AMD Ryzen 3 2300U Firmware | <raven-fp5-am4_1.1.0.e | |
AMD Ryzen 3 2300U | ||
AMD Ryzen 5 2500U Firmware | <raven-fp5-am4_1.1.0.e | |
AMD Ryzen 5 2500U | ||
AMD Ryzen 5 2600H Firmware | <raven-fp5-am4_1.1.0.e | |
AMD Ryzen 5 2600H | ||
AMD Ryzen 7 2700U Firmware | <raven-fp5-am4_1.1.0.e | |
AMD Ryzen 7 2700U Firmware | ||
AMD Ryzen 7 2800H Firmware | <raven-fp5-am4_1.1.0.e | |
AMD Ryzen 7 2800H Firmware | ||
AMD Ryzen 3 2200U Firmware | <pinnaclepi-am4_1.0.0.c_\(rv1\) | |
AMD Ryzen 3 2300U Firmware | <pinnaclepi-am4_1.0.0.c_\(rv1\) | |
AMD Ryzen 5 2500U Firmware | <pinnaclepi-am4_1.0.0.c_\(rv1\) | |
AMD Ryzen 5 2600H Firmware | <pinnaclepi-am4_1.0.0.c_\(rv1\) | |
AMD Ryzen 7 2700U Firmware | <pinnaclepi-am4_1.0.0.c_\(rv1\) | |
AMD Ryzen 7 2800H Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 3 2200U Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 3 2300U Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 5 2500U Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 5 2600H Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 7 2700U Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 7 2800H Firmware | <comboam4v2_pi_1.2.0.6c | |
AMD Ryzen 3 2200U Firmware | <comboam4v2_pi_1.2.0.6c | |
AMD Ryzen 3 2300U Firmware | <comboam4v2_pi_1.2.0.6c | |
AMD Ryzen 5 2500U Firmware | <comboam4v2_pi_1.2.0.6c | |
AMD Ryzen 5 2600H Firmware | <comboam4v2_pi_1.2.0.6c | |
AMD Ryzen 7 2700U Firmware | <comboam4v2_pi_1.2.0.6c | |
AMD Ryzen 3 2200U Firmware | <picassopi-fp5_1.0.0.d | |
AMD Ryzen 3 2300U Firmware | <picassopi-fp5_1.0.0.d | |
AMD Ryzen 5 2500U Firmware | <picassopi-fp5_1.0.0.d | |
AMD Ryzen 5 2600H Firmware | <picassopi-fp5_1.0.0.d | |
AMD Ryzen 7 2700U Firmware | <picassopi-fp5_1.0.0.d | |
AMD Ryzen 7 2800H Firmware | <picassopi-fp5_1.0.0.d | |
AMD Ryzen 3 3200U Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 3 3200U Firmware | ||
AMD Ryzen 3 3250U Firmware | <comboam4pi_1.0.0.8 | |
AMD Ryzen 3 3250U Firmware | ||
AMD Ryzen 3 3200U Firmware | <comboam4v2_pi_1.2.0.6c | |
AMD Ryzen 3 3250U Firmware | <comboam4v2_pi_1.2.0.6c | |
AMD Ryzen 3 3200U Firmware | <renoirpi-fp6_1.0.0.7 | |
AMD Ryzen 3 3250U Firmware | <renoirpi-fp6_1.0.0.7 | |
AMD Ryzen 7 2700X | <raven-fp5-am4_1.1.0.e | |
AMD Ryzen 7 2700 Firmware | <raven-fp5-am4_1.1.0.e | |
AMD Ryzen 3 5300U Firmware | <cezannepi-fp6_1.0.0._9a | |
AMD Ryzen 3 5300U Firmware | ||
AMD Ryzen 5 5500U Firmware | <cezannepi-fp6_1.0.0._9a | |
AMD Ryzen 5 5500U | ||
AMD Ryzen 7 5700U Firmware | <cezannepi-fp6_1.0.0._9a | |
AMD Ryzen 7 5700U Firmware | ||
AMD Ryzen 3 5125C Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 3 5125C | ||
AMD Ryzen 3 5400U Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 3 5400U | ||
AMD Ryzen 3 5425U | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 3 5425U | ||
AMD Ryzen 5 5560U Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 5 5560U Firmware | ||
AMD Ryzen 5 5600U Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 5 5600U | ||
AMD Ryzen 5 5625U Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 5 5625U Firmware | ||
AMD Ryzen 5 5600H Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 5 5600H | ||
AMD Ryzen 5 5600HS Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 5 5600HS | ||
AMD Ryzen 7 5800U Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 7 5800U Firmware | ||
AMD Ryzen 7 5825U Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 7 5825U Firmware | ||
AMD Ryzen 7 5800H Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 7 5800H Firmware | ||
AMD Ryzen 7 5800HS Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 7 5800HS Firmware | ||
AMD Ryzen 9 5900HS Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 9 5900HS Firmware | ||
AMD Ryzen 9 5900HX Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 9 5900HX | ||
AMD Ryzen 9 5980HS Firmware | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 9 5980HS Firmware | ||
AMD Ryzen 9 5980HX | <cezannepi-fp6_1.0.0.9 | |
AMD Ryzen 9 5980HX Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26388 has a severity rating of medium, indicating that it may result in a denial of service due to improper validation of the BIOS directory.
To remediate CVE-2021-26388, update the affected AMD EPYC 7232p, 7302p, 7402p, 7502p, 7702p, and other related firmware to a version higher than romepi-sp3_1.0.0.d.
CVE-2021-26388 affects various AMD EPYC firmware products, specifically those versions below romepi-sp3_1.0.0.d.
CVE-2021-26388 represents an improper validation vulnerability, potentially exposing out of bounds memory contents.
While CVE-2021-26388 primarily results in a denial of service, exposing out of bounds memory could theoretically lead to sensitive data exposure.