CVE-2021-44850: Buffer Overflow

Published Feb 10, 2022
·
Updated

On Xilinx Zynq-7000 SoC devices, physical modification of an SD boot image allows for a buffer overflow attack in the ROM. Because the Zynq-7000's boot image header is unencrypted and unauthenticated before use, an attacker can modify the boot header stored on an SD card so that a secure image appears to be unencrypted, and they will be able to modify the full range of register initialization values. Normally, these registers will be restricted when booting securely. Of importance to this attack are two registers that control the SD card's transfer type and transfer size. These registers could be modified a way that causes a buffer overflow in the ROM.

Affected Software

20 affected components
AMD Xilinx Z-7012s Firmware
AMD Xilinx Z-7012s
AMD Xilinx Z-7014s Firmware
AMD Xilinx Z-7014s
AMD Xilinx Z-7010 Firmware
AMD Xilinx Z-7010
AMD Xilinx Z-7015 Firmware
AMD Xilinx Z-7015
AMD Xilinx Z-7020 Firmware
AMD Xilinx Z-7020
AMD Xilinx Z-7030 Firmware
AMD Xilinx Z-7030
AMD Xilinx Z-7035 Firmware
AMD Xilinx Z-7035
AMD Xilinx Z-7045 Firmware
AMD Xilinx Z-7045
AMD Xilinx Z-7100 Firmware
AMD Xilinx Z-7100
AMD Xilinx Z-7007s Firmware
AMD Xilinx Z-7007s

Event History

Feb 10, 2022
CVE Published
via MITRE·06:19 PM
Data Sourced
via MITRE·06:19 PM
Description
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for this vulnerability?

The vulnerability ID for this vulnerability is CVE-2021-44850.

2

What devices are affected by this vulnerability?

On Xilinx Zynq-7000 SoC devices are affected by this vulnerability.

3

What is the severity of CVE-2021-44850?

The severity of CVE-2021-44850 is medium.

4

How can an attacker exploit this vulnerability?

An attacker can exploit this vulnerability by physically modifying an SD boot image to perform a buffer overflow attack in the ROM.

5

Is there a fix available for CVE-2021-44850?

Yes, a fix is available for CVE-2021-44850. Please refer to the Xilinx support articles for more information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
CVE-2021-44850 - Buffer Overflow - SecAlerts