CVE-2021-46779: Input Validation
Insufficient input validation in SVCECCPRIMITIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential loss of integrity and availability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-46779?
CVE-2021-46779 is a vulnerability that allows an attacker to corrupt ASP (AMD Secure Processor) OS memory, potentially leading to loss of integrity and availability.
What is the severity of CVE-2021-46779?
CVE-2021-46779 has a severity rating of 7.1 (high).
Which software is affected by CVE-2021-46779?
AMD Romepi Firmware versions up to exclusive 1.0.0.c, AMD Milanpi Firmware versions up to exclusive 1.0.0.4, and AMD Naplespi Firmware versions up to exclusive 1.0.0.g are affected by CVE-2021-46779.
How can an attacker exploit CVE-2021-46779?
An attacker can exploit CVE-2021-46779 through a compromised user application or ABL by manipulating the SVC_ECC_PRIMITIVE system call to corrupt ASP OS memory.
Is AMD Romepi, AMD Milanpi, or AMD Naplespi vulnerable to CVE-2021-46779?
AMD Romepi, AMD Milanpi, and AMD Naplespi are not vulnerable to CVE-2021-46779.
How can I fix CVE-2021-46779?
To fix CVE-2021-46779, it is recommended to apply the necessary firmware updates provided by AMD.
Where can I find more information about CVE-2021-46779?
More information about CVE-2021-46779 can be found on the AMD Product Security Bulletin at https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-1032.