Vulnerability Description
A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior inside the virtual machine (VM).
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Epyc 7001 Firmware | - |
| Amd | Epyc 7001 | - |
| Amd | Epyc 7232P Firmware | - |
| Amd | Epyc 7232P | - |
| Amd | Epyc 7251 Firmware | - |
| Amd | Epyc 7251 | - |
| Amd | Epyc 7261 Firmware | - |
| Amd | Epyc 7261 | - |
| Amd | Epyc 7252 Firmware | - |
| Amd | Epyc 7252 | - |
| Amd | Epyc 74F3 Firmware | - |
| Amd | Epyc 74F3 | - |
| Amd | Epyc 7501 Firmware | - |
| Amd | Epyc 7501 | - |
| Amd | Epyc 7502 Firmware | - |
| Amd | Epyc 7502 | - |
| Amd | Epyc 7502P Firmware | - |
| Amd | Epyc 7502P | - |
| Amd | Epyc 7513 Firmware | - |
| Amd | Epyc 7513 | - |
References
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1023Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1023Vendor Advisory
FAQ
What is CVE-2021-26340?
CVE-2021-26340 is a vulnerability with a CVSS score of 8.4 (HIGH). A malicious hypervisor in conjunction with an unprivileged attacker process inside an SEV/SEV-ES guest VM may fail to flush the Translation Lookaside Buffer (TLB) resulting in unexpected behavior insi...
How severe is CVE-2021-26340?
CVE-2021-26340 has been rated HIGH with a CVSS base score of 8.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26340?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Epyc 7001 Firmware, Amd Epyc 7001, Amd Epyc 7232P Firmware, Amd Epyc 7232P, Amd Epyc 7251 Firmware.