Vulnerability Name:

CVE-2021-26342 (CCN-226271)

Assigned:2021-01-29
Published:2022-05-10
Updated:2022-05-19
Summary:In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV-SNP guest VMs are not impacted by this vulnerability.
CVSS v3 Severity:3.3 Low (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N)
2.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
3.5 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2021-26342

Source: XF
Type: UNKNOWN
amd-cve202126342-info-disc(226271)

Source: CCN
Type: AMD-SB-1028
AMD Server Vulnerabilities - May 2022

Source: MISC
Type: Vendor Advisory
https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1028

Vulnerable Configuration:Configuration 1:
  • cpe:/o:amd:epyc_7763_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7763:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:amd:epyc_7713p_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7713p:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:amd:epyc_7713_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7713:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:amd:epyc_7663_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7663:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:amd:epyc_7643_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7643:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:amd:epyc_75f3_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_75f3:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:amd:epyc_7543p_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7543p:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:amd:epyc_7543_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7543:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:amd:epyc_7513_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7513:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:amd:epyc_7453_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7453:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:amd:epyc_74f3_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_74f3:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:amd:epyc_7443p_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7443p:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:amd:epyc_7443_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7443:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:amd:epyc_7413_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7413:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:amd:epyc_73f3_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_73f3:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:amd:epyc_7343_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7343:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:amd:epyc_7313p_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7313p:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:amd:epyc_7313_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7313:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:amd:epyc_72f3_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_72f3:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:amd:epyc_7773x_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7773x:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:amd:epyc_7473x_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7473x:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:amd:epyc_7573x_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7573x:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:amd:epyc_7373x_firmware:*:*:*:*:*:*:*:* (Version < milanpi-sp3_1.0.0.7)
  • AND
  • cpe:/h:amd:epyc_7373x:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:amd:epyc_7001_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7001:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:amd:epyc_7251_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7251:-:*:*:*:*:*:*:*

  • Configuration 26:
  • cpe:/o:amd:epyc_7261_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7261:-:*:*:*:*:*:*:*

  • Configuration 27:
  • cpe:/o:amd:epyc_7281_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7281:-:*:*:*:*:*:*:*

  • Configuration 28:
  • cpe:/o:amd:epyc_7301_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7301:-:*:*:*:*:*:*:*

  • Configuration 29:
  • cpe:/o:amd:epyc_7351_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7351:-:*:*:*:*:*:*:*

  • Configuration 30:
  • cpe:/o:amd:epyc_7351p_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7351p:-:*:*:*:*:*:*:*

  • Configuration 31:
  • cpe:/o:amd:epyc_7371_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7371:-:*:*:*:*:*:*:*

  • Configuration 32:
  • cpe:/o:amd:epyc_7401_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7401:-:*:*:*:*:*:*:*

  • Configuration 33:
  • cpe:/o:amd:epyc_7401p_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7401p:-:*:*:*:*:*:*:*

  • Configuration 34:
  • cpe:/o:amd:epyc_7451_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7451:-:*:*:*:*:*:*:*

  • Configuration 35:
  • cpe:/o:amd:epyc_7501_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7501:-:*:*:*:*:*:*:*

  • Configuration 36:
  • cpe:/o:amd:epyc_7551_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7551:-:*:*:*:*:*:*:*

  • Configuration 37:
  • cpe:/o:amd:epyc_7551p_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7551p:-:*:*:*:*:*:*:*

  • Configuration 38:
  • cpe:/o:amd:epyc_7601_firmware:*:*:*:*:*:*:*:* (Version < naplespi-sp3_1.0.0.h)
  • AND
  • cpe:/h:amd:epyc_7601:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:95239
    P
    Security update for kernel-firmware (Important)
    2022-06-02
    oval:org.opensuse.security:def:3609
    P
    Security update for kernel-firmware (Important)
    2022-06-02
    oval:org.opensuse.security:def:511
    P
    Security update for kernel-firmware (Important)
    2022-06-02
    oval:org.opensuse.security:def:900
    P
    Security update for kernel-firmware (Moderate)
    2022-05-25
    oval:org.opensuse.security:def:42293
    P
    Security update for kernel-firmware (Moderate)
    2022-05-25
    oval:org.opensuse.security:def:42389
    P
    Security update for kernel-firmware (Moderate)
    2022-05-25
    BACK
    amd epyc 7763 firmware *
    amd epyc 7763 -
    amd epyc 7713p firmware *
    amd epyc 7713p -
    amd epyc 7713 firmware *
    amd epyc 7713 -
    amd epyc 7663 firmware *
    amd epyc 7663 -
    amd epyc 7643 firmware *
    amd epyc 7643 -
    amd epyc 75f3 firmware *
    amd epyc 75f3 -
    amd epyc 7543p firmware *
    amd epyc 7543p -
    amd epyc 7543 firmware *
    amd epyc 7543 -
    amd epyc 7513 firmware *
    amd epyc 7513 -
    amd epyc 7453 firmware *
    amd epyc 7453 -
    amd epyc 74f3 firmware *
    amd epyc 74f3 -
    amd epyc 7443p firmware *
    amd epyc 7443p -
    amd epyc 7443 firmware *
    amd epyc 7443 -
    amd epyc 7413 firmware *
    amd epyc 7413 -
    amd epyc 73f3 firmware *
    amd epyc 73f3 -
    amd epyc 7343 firmware *
    amd epyc 7343 -
    amd epyc 7313p firmware *
    amd epyc 7313p -
    amd epyc 7313 firmware *
    amd epyc 7313 -
    amd epyc 72f3 firmware *
    amd epyc 72f3 -
    amd epyc 7773x firmware *
    amd epyc 7773x -
    amd epyc 7473x firmware *
    amd epyc 7473x -
    amd epyc 7573x firmware *
    amd epyc 7573x -
    amd epyc 7373x firmware *
    amd epyc 7373x -
    amd epyc 7001 firmware *
    amd epyc 7001 -
    amd epyc 7251 firmware *
    amd epyc 7251 -
    amd epyc 7261 firmware *
    amd epyc 7261 -
    amd epyc 7281 firmware *
    amd epyc 7281 -
    amd epyc 7301 firmware *
    amd epyc 7301 -
    amd epyc 7351 firmware *
    amd epyc 7351 -
    amd epyc 7351p firmware *
    amd epyc 7351p -
    amd epyc 7371 firmware *
    amd epyc 7371 -
    amd epyc 7401 firmware *
    amd epyc 7401 -
    amd epyc 7401p firmware *
    amd epyc 7401p -
    amd epyc 7451 firmware *
    amd epyc 7451 -
    amd epyc 7501 firmware *
    amd epyc 7501 -
    amd epyc 7551 firmware *
    amd epyc 7551 -
    amd epyc 7551p firmware *
    amd epyc 7551p -
    amd epyc 7601 firmware *
    amd epyc 7601 -