CVE-2021-26365
Last modified
CVE-2021-26365 is a high-severity vulnerability rated 8.2/10 on the CVSS scale. Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents. . EPSS estimates a 0.57% chance of exploitation in the next 30 days.
Description
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 5 2400g Firmware | All versions |
| Amd | Ryzen 5 2400ge Firmware | All versions |
| Amd | Ryzen 3 2200ge Firmware | All versions |
| Amd | Ryzen 3 2200g Firmware | All versions |
| Amd | Ryzen 3 Pro 2100ge Firmware | All versions |
| Amd | Ryzen 9 5900x Firmware | All versions |
| Amd | Ryzen 9 5950x Firmware | All versions |
| Amd | Ryzen 9 5900 Firmware | All versions |
| Amd | Ryzen 7 5800 Firmware | All versions |
| Amd | Ryzen 7 5800x Firmware | All versions |
| Amd | Ryzen 7 5800x3d Firmware | All versions |
| Amd | Ryzen 7 5700x Firmware | All versions |
| Amd | Ryzen 5 5600 Firmware | All versions |
| Amd | Ryzen 5 5600x Firmware | All versions |
| Amd | Ryzen 5 5500 Firmware | All versions |
| Amd | Ryzen 3 3200u Firmware | < picassopi-fp5_1.0.0.d |
| Amd | Ryzen 3 3250c Firmware | < picassopi-fp5_1.0.0.d |
| Amd | Ryzen 3 3250u Firmware | < picassopi-fp5_1.0.0.d |
| Amd | Amd 3015e Firmware | < pollockpi-ft5_1.0.0.3 |
| Amd | Amd 3015ce Firmware | < pollockpi-ft5_1.0.0.3 |
| Amd | Ryzen 7 2800h Firmware | All versions |
| Amd | Ryzen 7 2700u Firmware | All versions |
| Amd | Ryzen 5 2600h Firmware | All versions |
| Amd | Ryzen 5 2500u Firmware | All versions |
| Amd | Ryzen 3 2300u Firmware | All versions |
| Amd | Ryzen 3 2200u Firmware | All versions |
| Amd | Ryzen 5 3400g Firmware | All versions |
| Amd | Ryzen 5 Pro 3400g Firmware | All versions |
| Amd | Ryzen 5 Pro 3400ge Firmware | All versions |
| Amd | Ryzen 5 Pro 3350g Firmware | All versions |
| Amd | Ryzen 5 Pro 3350ge Firmware | All versions |
| Amd | Ryzen 3 Pro 3200g Firmware | All versions |
| Amd | Ryzen 3 3200g Firmware | All versions |
| Amd | Ryzen 3 3200ge Firmware | All versions |
| Amd | Ryzen 3 Pro 3200ge Firmware | All versions |
| Amd | Ryzen 7 5700u Firmware | < cezannepi-fp6_1.0.0.8 |
| Amd | Ryzen 5 5500u Firmware | < cezannepi-fp6_1.0.0.8 |
| Amd | Ryzen 3 5300u Firmware | < cezannepi-fp6_1.0.0.8 |
| Amd | Ryzen 7 5700g Firmware | < cezannepi-fp6_1.0.0.8 |
| Amd | Ryzen 7 5700ge Firmware | < cezannepi-fp6_1.0.0.8 |
| Amd | Ryzen 5 5600g Firmware | < cezannepi-fp6_1.0.0.8 |
| Amd | Ryzen 5 5600ge Firmware | < cezannepi-fp6_1.0.0.8 |
| Amd | Ryzen 3 5300g Firmware | < cezannepi-fp6_1.0.0.8 |
| Amd | Ryzen 3 5300ge Firmware | < cezannepi-fp6_1.0.0.8 |
| Amd | Ryzen 9 6980hx Firmware | < rmb_1.0.0.4 |
| Amd | Ryzen 9 6980hs Firmware | < rmb_1.0.0.4 |
| Amd | Ryzen 9 6900hx Firmware | < rmb_1.0.0.4 |
| Amd | Ryzen 9 6900hs Firmware | < rmb_1.0.0.4 |
| Amd | Ryzen 7 6800h Firmware | < rmb_1.0.0.4 |
| Amd | Ryzen 7 6800hs Firmware | < rmb_1.0.0.4 |
Showing 50 of 54 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26365?
How severe is CVE-2021-26365?
How do I fix CVE-2021-26365?
Are you affected by CVE-2021-26365?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
