Vulnerability Description
A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when triggering an SMI resulting in a potential loss of resources.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 7 5700G Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 7 5700G | - |
| Amd | Ryzen 7 5700Ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 7 5700Ge | - |
| Amd | Ryzen 5 5600G Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 5 5600G | - |
| Amd | Ryzen 5 5600Ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 5 5600Ge | - |
| Amd | Ryzen 3 5300G Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 3 5300G | - |
| Amd | Ryzen 3 5300Ge Firmware | < comboam4_v2_pi_1.2.0.6c |
| Amd | Ryzen 3 5300Ge | - |
| Amd | Ryzen 9 5980Hx Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5980Hx | - |
| Amd | Ryzen 9 5980Hs Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5980Hs | - |
| Amd | Ryzen 7 5825U Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 7 5825U | - |
| Amd | Ryzen 9 5900Hx Firmware | < cezannepi-fp6_1.0.0.9 |
| Amd | Ryzen 9 5900Hx | - |
Related Weaknesses (CWE)
References
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027Vendor Advisory
FAQ
What is CVE-2021-26384?
CVE-2021-26384 is a vulnerability with a CVSS score of 7.8 (HIGH). A malformed SMI (System Management Interface) command may allow an attacker to establish a corrupted SMI Trigger Info data structure, potentially leading to out-of-bounds memory reads and writes when ...
How severe is CVE-2021-26384?
CVE-2021-26384 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-26384?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 7 5700G Firmware, Amd Ryzen 7 5700G, Amd Ryzen 7 5700Ge Firmware, Amd Ryzen 7 5700Ge, Amd Ryzen 5 5600G Firmware.