Vulnerability Description
Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Radeon Software | - |
| Amd | Ryzen 3 2200U Firmware | - |
| Amd | Ryzen 3 2200U | - |
| Amd | Ryzen 5300G Firmware | - |
| Amd | Ryzen 5300G | - |
| Amd | Ryzen 5300Ge Firmware | - |
| Amd | Ryzen 5300Ge | - |
| Amd | Ryzen 5600G Firmware | - |
| Amd | Ryzen 5600G | - |
| Amd | Ryzen 5600Ge Firmware | - |
| Amd | Ryzen 5600Ge | - |
| Amd | Ryzen 5600X Firmware | - |
| Amd | Ryzen 5600X | - |
| Amd | Ryzen 5700G Firmware | - |
| Amd | Ryzen 5700G | - |
| Amd | Ryzen 5700Ge Firmware | - |
| Amd | Ryzen 5700Ge | - |
| Amd | Athlon 3050Ge Firmware | - |
| Amd | Athlon 3050Ge | - |
| Amd | Athlon 3150G Firmware | - |
References
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
FAQ
What is CVE-2021-26317?
CVE-2021-26317 is a vulnerability with a CVSS score of 7.8 (HIGH). Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.
How severe is CVE-2021-26317?
CVE-2021-26317 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26317?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Radeon Software, Amd Ryzen 3 2200U Firmware, Amd Ryzen 3 2200U, Amd Ryzen 5300G Firmware, Amd Ryzen 5300G.