Vulnerability Description
An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for authenticating an ACP firmware image, potentially resulting in a denial of service.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 7 5700G Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 7 5700G | - |
| Amd | Ryzen 7 5700Ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 7 5700Ge | - |
| Amd | Ryzen 5 5600G Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 5 5600G | - |
| Amd | Ryzen 5 5600Ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 5 5600Ge | - |
| Amd | Ryzen 3 5300G Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 3 5300G | - |
| Amd | Ryzen 3 5300Ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 3 5300Ge | - |
| Amd | Ryzen 9 5980Hx Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5980Hx | - |
| Amd | Ryzen 9 5980Hs Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5980Hs | - |
| Amd | Ryzen 7 5825U Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 7 5825U | - |
| Amd | Ryzen 9 5900Hx Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5900Hx | - |
References
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
FAQ
What is CVE-2021-26382?
CVE-2021-26382 is a vulnerability with a CVSS score of 4.4 (MEDIUM). An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for auth...
How severe is CVE-2021-26382?
CVE-2021-26382 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26382?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 7 5700G Firmware, Amd Ryzen 7 5700G, Amd Ryzen 7 5700Ge Firmware, Amd Ryzen 7 5700Ge, Amd Ryzen 5 5600G Firmware.