Vulnerability Description
Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 5 2400G Firmware | - |
| Amd | Ryzen 5 2400G | - |
| Amd | Ryzen 5 2400Ge Firmware | - |
| Amd | Ryzen 5 2400Ge | - |
| Amd | Ryzen 3 2200Ge Firmware | - |
| Amd | Ryzen 3 2200Ge | - |
| Amd | Ryzen 3 2200G Firmware | - |
| Amd | Ryzen 3 2200G | - |
| Amd | Ryzen 3 Pro 2100Ge Firmware | - |
| Amd | Ryzen 3 Pro 2100Ge | - |
| Amd | Ryzen 9 5900X Firmware | - |
| Amd | Ryzen 9 5900X | - |
| Amd | Ryzen 9 5950X Firmware | - |
| Amd | Ryzen 9 5950X | - |
| Amd | Ryzen 9 5900 Firmware | - |
| Amd | Ryzen 9 5900 | - |
| Amd | Ryzen 7 5800 Firmware | - |
| Amd | Ryzen 7 5800 | - |
| Amd | Ryzen 7 5800X Firmware | - |
| Amd | Ryzen 7 5800X | - |
Related Weaknesses (CWE)
References
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4001Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4001Vendor Advisory
FAQ
What is CVE-2021-26365?
CVE-2021-26365 is a vulnerability with a CVSS score of 8.2 (HIGH). Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bo...
How severe is CVE-2021-26365?
CVE-2021-26365 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26365?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 5 2400G Firmware, Amd Ryzen 5 2400G, Amd Ryzen 5 2400Ge Firmware, Amd Ryzen 5 2400Ge, Amd Ryzen 3 2200Ge Firmware.