Vulnerability Description
Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a potential denial of service.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Amd | Ryzen 5500 Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5500 | - |
| Amd | Ryzen 5600 Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5600 | - |
| Amd | Ryzen 5600G Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5600G | - |
| Amd | Ryzen 5600X Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5600X | - |
| Amd | Ryzen 5700G Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5700G | - |
| Amd | Ryzen 5700X Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5700X | - |
| Amd | Ryzen 5800X3D Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5800X3D | - |
| Amd | Ryzen 5800X Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5800X | - |
| Amd | Ryzen 5900X Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5900X | - |
| Amd | Ryzen 5950X Firmware | comboam4_v2_pi_1.2.0.8 |
| Amd | Ryzen 5950X | - |
References
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4001Vendor Advisory
- https://www.amd.com/en/corporate/product-security/bulletin/AMD-SB-4001Vendor Advisory
FAQ
What is CVE-2021-46755?
CVE-2021-46755 is a vulnerability with a CVSS score of 7.5 (HIGH). Failure to unmap certain SysHub mappings in error paths of the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicious bootloader to exhaust the SysHub resources resulting in a po...
How severe is CVE-2021-46755?
CVE-2021-46755 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-46755?
Check the references section above for vendor advisories and patch information. Affected products include: Amd Ryzen 5500 Firmware, Amd Ryzen 5500, Amd Ryzen 5600 Firmware, Amd Ryzen 5600, Amd Ryzen 5600G Firmware.