Vulnerability Description
A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Radeon Software | - |
| Amd | Ryzen 3 3100 Firmware | - |
| Amd | Ryzen 3 3100 | - |
| Amd | Ryzen 3 3300G Firmware | - |
| Amd | Ryzen 3 3300G | - |
| Amd | Ryzen 3 3300X Firmware | - |
| Amd | Ryzen 3 3300X | - |
| Amd | Ryzen 3 5400U Firmware | - |
| Amd | Ryzen 3 5400U | - |
| Amd | Ryzen 9 5900Hs Firmware | - |
| Amd | Ryzen 9 5900Hs | - |
| Amd | Ryzen 9 5900Hx Firmware | - |
| Amd | Ryzen 9 5900Hx | - |
| Amd | Ryzen 9 5980Hs Firmware | - |
| Amd | Ryzen 9 5980Hs | - |
| Amd | Ryzen 9 5980Hx Firmware | - |
| Amd | Ryzen 9 5980Hx | - |
| Amd | Ryzen 3 5125C Firmware | - |
| Amd | Ryzen 3 5125C | - |
| Amd | Ryzen 3 5425C Firmware | - |
References
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
FAQ
What is CVE-2021-26363?
CVE-2021-26363 is a vulnerability with a CVSS score of 4.4 (MEDIUM). A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.
How severe is CVE-2021-26363?
CVE-2021-26363 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26363?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Radeon Software, Amd Ryzen 3 3100 Firmware, Amd Ryzen 3 3100, Amd Ryzen 3 3300G Firmware, Amd Ryzen 3 3300G.