First published: Tue May 10 2022(Updated: )
Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.
Credit: psirt@amd.com
Affected Software | Affected Version | How to fix |
---|---|---|
AMD EPYC 7002 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7002 | ||
Amd Epyc Server Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7001 Firmware | ||
AMD EPYC 7232p firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7232p firmware | ||
AMD EPYC 7252 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7252 Firmware | ||
AMD EPYC 7262 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7262 Firmware | ||
AMD EPYC 7272 firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7272 firmware | ||
AMD EPYC 7282 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7282 Firmware | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7302 Firmware | ||
AMD EPYC 7302P Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7302P Firmware | ||
AMD EPYC 7352 firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7352 firmware | ||
Amd Epyc Server Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7402 Firmware | ||
AMD EPYC 7402P Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7402P Firmware | ||
AMD EPYC 7452 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7452 | ||
AMD EPYC 7502P Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7502 firmware | ||
AMD EPYC 7502P Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7502P Firmware | ||
AMD EPYC 7532 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7532 Firmware | ||
AMD EPYC 7542 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7542 | ||
AMD EPYC 7552 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7552 Firmware | ||
AMD EPYC 7642 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7642 Firmware | ||
AMD EPYC 7662 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7662 Firmware | ||
AMD EPYC 7702 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7702 | ||
AMD EPYC 7702 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7702p | ||
AMD EPYC 7742 firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7742 firmware | ||
AMD EPYC 7F32 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7F32 Firmware | ||
AMD EPYC 7F52 Firmware | <romepi-sp3_1.0.0.c | |
AMD EPYC 7F52 Firmware | ||
AMD EPYC 7F72 | <romepi-sp3_1.0.0.c | |
AMD EPYC 7F72 Firmware | ||
AMD EPYC 7251 Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7251 Firmware | ||
Amd Epyc Server Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7281 Firmware | ||
Amd Epyc Server Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7301 Firmware | ||
AMD EPYC 7351P Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7351 Firmware | ||
AMD EPYC 7351P Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7351P Firmware | ||
AMD EPYC 7401P Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7401 Firmware | ||
AMD EPYC 7401P Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7401P Firmware | ||
AMD EPYC 7451 Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7451 Firmware | ||
AMD EPYC 7501 firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7501 | ||
AMD EPYC 7551P Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7551 Firmware | ||
AMD EPYC 7551P Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7551P Firmware | ||
AMD EPYC 7601 Firmware | <naplespi-sp3_1.0.0.g | |
AMD EPYC 7601 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-26408 has a severity rating indicating potential loss of integrity or confidentiality for affected AMD Epyc 7001 and 7002 firmware.
To fix CVE-2021-26408, upgrade to the patched firmware versions provided by AMD, specifically those released after romepi-sp3_1.0.0.c for Epyc 7002 and romepi-sp3_1.0.0.c for Epyc 7001.
CVE-2021-26408 affects AMD Epyc 7001 and 7002 firmware versions up to romepi-sp3_1.0.0.c and naplespi-sp3_1.0.0.g.
If left unaddressed, CVE-2021-26408 may allow an attacker to compromise the integrity and confidentiality of SEV-legacy guests.
CVE-2021-26408 is considered a software vulnerability related to insufficient validation in SEV-legacy firmware.