CVE-2021-26408: High severity amd epyc 7002 firmware vulnerability
Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-26408?
CVE-2021-26408 has a severity rating indicating potential loss of integrity or confidentiality for affected AMD Epyc 7001 and 7002 firmware.
How do I fix CVE-2021-26408?
To fix CVE-2021-26408, upgrade to the patched firmware versions provided by AMD, specifically those released after romepi-sp3_1.0.0.c for Epyc 7002 and romepi-sp3_1.0.0.c for Epyc 7001.
What products are affected by CVE-2021-26408?
CVE-2021-26408 affects AMD Epyc 7001 and 7002 firmware versions up to romepi-sp3_1.0.0.c and naplespi-sp3_1.0.0.g.
What can happen if I don't address CVE-2021-26408?
If left unaddressed, CVE-2021-26408 may allow an attacker to compromise the integrity and confidentiality of SEV-legacy guests.
Is CVE-2021-26408 a hardware or software vulnerability?
CVE-2021-26408 is considered a software vulnerability related to insufficient validation in SEV-legacy firmware.