CVE-2021-26393
Last modified
CVE-2021-26393 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amd | Enterprise Driver | < 22.10.20 |
| Amd | Radeon Pro Software | < 22.q2 |
| Amd | Radeon Software | < 22.5.2 |
| Amd | Radeon Rx Vega 56 Firmware | All versions |
| Amd | Radeon Rx Vega 64 Firmware | All versions |
| Amd | Ryzen 3 2200ge Firmware | All versions |
| Amd | Ryzen 3 2200g Firmware | All versions |
| Amd | Ryzen 5 2400ge Firmware | All versions |
| Amd | Ryzen 5 2400g Firmware | All versions |
| Amd | Ryzen 3 5300ge Firmware | All versions |
| Amd | Ryzen 3 5300g Firmware | All versions |
| Amd | Ryzen 5 5600ge Firmware | All versions |
| Amd | Ryzen 5 5600g Firmware | All versions |
| Amd | Ryzen 7 5700ge Firmware | All versions |
| Amd | Ryzen 7 5700g Firmware | All versions |
| Amd | Athlon Silver 3050e Firmware | All versions |
| Amd | Athlon Pro 3045b Firmware | All versions |
| Amd | Athlon Silver 3050u Firmware | All versions |
| Amd | Athlon Silver 3050c Firmware | All versions |
| Amd | Athlon Pro 3145b Firmware | All versions |
| Amd | Athlon Gold 3150u Firmware | All versions |
| Amd | Athlon Gold 3150c Firmware | All versions |
| Amd | Ryzen 3 3250u Firmware | All versions |
| Amd | Ryzen 3 3250c Firmware | All versions |
| Amd | Amd 3020e Firmware | All versions |
| Amd | Amd 3015e Firmware | All versions |
| Amd | Amd 3015ce Firmware | All versions |
| Amd | Ryzen 3 2200u Firmware | All versions |
| Amd | Ryzen 3 2300u Firmware | All versions |
| Amd | Ryzen 5 2500u Firmware | All versions |
| Amd | Ryzen 5 2600h Firmware | All versions |
| Amd | Ryzen 7 2700u Firmware | All versions |
| Amd | Ryzen 7 2800h Firmware | All versions |
| Amd | Ryzen 3 3300u Firmware | All versions |
| Amd | Ryzen 3 3350u Firmware | All versions |
| Amd | Ryzen 5 3450u Firmware | All versions |
| Amd | Ryzen 5 3500u Firmware | All versions |
| Amd | Ryzen 5 3500c Firmware | All versions |
| Amd | Ryzen 5 3550h Firmware | All versions |
| Amd | Ryzen 5 3580u Firmware | All versions |
| Amd | Ryzen 7 3700u Firmware | All versions |
| Amd | Ryzen 7 3700c Firmware | All versions |
| Amd | Ryzen 7 3750h Firmware | All versions |
| Amd | Ryzen 7 3780u Firmware | All versions |
| Amd | Ryzen 3 Pro 3200ge Firmware | All versions |
| Amd | Ryzen 3 3200g Firmware | All versions |
| Amd | Ryzen 3 Pro 3200g Firmware | All versions |
| Amd | Ryzen 5 Pro 3350ge Firmware | All versions |
| Amd | Ryzen 5 Pro 3350g Firmware | All versions |
| Amd | Ryzen 5 Pro 3400ge Firmware | All versions |
Showing 50 of 67 affected configurations. See NVD for the full list.
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-26393?
How severe is CVE-2021-26393?
How do I fix CVE-2021-26393?
Are you affected by CVE-2021-26393?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
