CRITICAL · 9.8

CVE-2021-26379

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.

Vulnerability Description

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
AmdEpyc 72F3 Firmware< milanpi_1.0.0.9
AmdEpyc 72F3-
AmdEpyc 7313 Firmware< milanpi_1.0.0.9
AmdEpyc 7313-
AmdEpyc 7313P Firmware< milanpi_1.0.0.9
AmdEpyc 7313P-
AmdEpyc 7343 Firmware< milanpi_1.0.0.9
AmdEpyc 7343-
AmdEpyc 7373X Firmware< milanpi_1.0.0.9
AmdEpyc 7373X-
AmdEpyc 73F3 Firmware< milanpi_1.0.0.9
AmdEpyc 73F3-
AmdEpyc 7413 Firmware< milanpi_1.0.0.9
AmdEpyc 7413-
AmdEpyc 7443 Firmware< milanpi_1.0.0.9
AmdEpyc 7443-
AmdEpyc 7443P Firmware< milanpi_1.0.0.9
AmdEpyc 7443P-
AmdEpyc 7453 Firmware< milanpi_1.0.0.9
AmdEpyc 7453-

References

FAQ

What is CVE-2021-26379?

CVE-2021-26379 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.

How severe is CVE-2021-26379?

CVE-2021-26379 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2021-26379?

Check the references section above for vendor advisories and patch information. Affected products include: Amd Epyc 72F3 Firmware, Amd Epyc 72F3, Amd Epyc 7313 Firmware, Amd Epyc 7313, Amd Epyc 7313P Firmware.