CVE-2021-26382
Last modified
CVE-2021-26382 is a medium-severity vulnerability rated 4.4/10 on the CVSS scale. An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for authenticating an ACP firmware image, potentially resulting in a denial of service.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for authenticating an ACP firmware image, potentially resulting in a denial of service.
Metrics
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 7 5700g Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 7 5700ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 5 5600g Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 5 5600ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 3 5300g Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 3 5300ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 9 5980hx Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5980hs Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 7 5825u Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5900hx Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5900hs Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 7 5825c Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 7 5800h Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 5 5625u Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 7 5800hs Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 5 5625c Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 5 5600h Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 5 5600hs Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 7 5800u Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 5 5600u Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 5 5560u Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 3 5425u Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 3 5425c Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 3 5400u Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 3 5125c Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 3 3200u Firmware | < renoirpi-fp6_1.0.0.7 |
| Amd | Ryzen 3 3250u Firmware | < renoirpi-fp6_1.0.0.7 |
| Amd | Ryzen 3 3300u Firmware | < renoirpi-fp6_1.0.0.7 |
| Amd | Ryzen 5 3500u Firmware | < renoirpi-fp6_1.0.0.7 |
| Amd | Ryzen 5 3550h Firmware | < renoirpi-fp6_1.0.0.7 |
| Amd | Ryzen 5 3580u Firmware | < renoirpi-fp6_1.0.0.7 |
| Amd | Ryzen 7 3700u Firmware | < renoirpi-fp6_1.0.0.7 |
| Amd | Ryzen 7 Pro 3700u Firmware | < renoirpi-fp6_1.0.0.7 |
| Amd | Ryzen 7 3750h Firmware | < renoirpi-fp6_1.0.0.7 |
| Amd | Ryzen 7 3780u Firmware | < renoirpi-fp6_1.0.0.7 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26382?
How severe is CVE-2021-26382?
How do I fix CVE-2021-26382?
Are you affected by CVE-2021-26382?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
