Vulnerability Name:

CVE-2021-26363 (CCN-226465)

Assigned:2021-01-29
Published:2022-05-10
Updated:2022-06-01
Summary:A malicious or compromised UApp or ABL could potentially change the value that the ASP uses for its reserved DRAM, to one outside of the fenced area, potentially leading to data exposure.
CVSS v3 Severity:4.4 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)
3.9 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
6.4 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)
5.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): High
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:3.6 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
6.0 Medium (CCN CVSS v2 Vector: AV:L/AC:H/Au:S/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): High
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-668
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2021-26363

Source: XF
Type: UNKNOWN
amd-cve202126363-info-disc(226465)

Source: CCN
Type: AMD-SB-1027
AMD Client Vulnerabilities - May 2022

Source: MISC
Type: Vendor Advisory
https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1027

Vulnerable Configuration:Configuration 1:
  • cpe:/a:amd:radeon_software:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:amd:ryzen_3_3100_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_3_3100:-:*:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/o:amd:ryzen_3_3300g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_3_3300g:-:*:*:*:*:*:*:*

  • Configuration 4:
  • cpe:/o:amd:ryzen_3_3300x_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_3_3300x:-:*:*:*:*:*:*:*

  • Configuration 5:
  • cpe:/o:amd:ryzen_3_5400u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_3_5400u:-:*:*:*:*:*:*:*

  • Configuration 6:
  • cpe:/o:amd:ryzen_9_5900hs_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_9_5900hs:-:*:*:*:*:*:*:*

  • Configuration 7:
  • cpe:/o:amd:ryzen_9_5900hx_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_9_5900hx:-:*:*:*:*:*:*:*

  • Configuration 8:
  • cpe:/o:amd:ryzen_9_5980hs_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_9_5980hs:-:*:*:*:*:*:*:*

  • Configuration 9:
  • cpe:/o:amd:ryzen_9_5980hx_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_9_5980hx:-:*:*:*:*:*:*:*

  • Configuration 10:
  • cpe:/o:amd:ryzen_3_5125c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_3_5125c:-:*:*:*:*:*:*:*

  • Configuration 11:
  • cpe:/o:amd:ryzen_3_5425c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_3_5425c:-:*:*:*:*:*:*:*

  • Configuration 12:
  • cpe:/o:amd:ryzen_7_3700x_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_7_3700x:-:*:*:*:*:*:*:*

  • Configuration 13:
  • cpe:/o:amd:ryzen_9_3900x_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_9_3900x:-:*:*:*:*:*:*:*

  • Configuration 14:
  • cpe:/o:amd:ryzen_9_3950x_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_9_3950x:-:*:*:*:*:*:*:*

  • Configuration 15:
  • cpe:/o:amd:ryzen_7_3800x_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_7_3800x:-:*:*:*:*:*:*:*

  • Configuration 16:
  • cpe:/o:amd:ryzen_3_5425u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_3_5425u:-:*:*:*:*:*:*:*

  • Configuration 17:
  • cpe:/o:amd:ryzen_5_3400g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_3400g:-:*:*:*:*:*:*:*

  • Configuration 18:
  • cpe:/o:amd:ryzen_7_5800h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_7_5800h:-:*:*:*:*:*:*:*

  • Configuration 19:
  • cpe:/o:amd:ryzen_7_5800hs_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_7_5800hs:-:*:*:*:*:*:*:*

  • Configuration 20:
  • cpe:/o:amd:ryzen_7_5800u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_7_5800u:-:*:*:*:*:*:*:*

  • Configuration 21:
  • cpe:/o:amd:ryzen_7_5825c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_7_5825c:-:*:*:*:*:*:*:*

  • Configuration 22:
  • cpe:/o:amd:ryzen_7_5825u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_7_5825u:-:*:*:*:*:*:*:*

  • Configuration 23:
  • cpe:/o:amd:ryzen_5_3450g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_3450g:-:*:*:*:*:*:*:*

  • Configuration 24:
  • cpe:/o:amd:ryzen_5_3600_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_3600:-:*:*:*:*:*:*:*

  • Configuration 25:
  • cpe:/o:amd:ryzen_5_3600x_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_3600x:-:*:*:*:*:*:*:*

  • Configuration 26:
  • cpe:/o:amd:ryzen_5_5560u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_5560u:-:*:*:*:*:*:*:*

  • Configuration 27:
  • cpe:/o:amd:ryzen_5_5600h_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_5600h:-:*:*:*:*:*:*:*

  • Configuration 28:
  • cpe:/o:amd:ryzen_5_5600u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_5600u:-:*:*:*:*:*:*:*

  • Configuration 29:
  • cpe:/o:amd:ryzen_5_5600hs_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_5600hs:-:*:*:*:*:*:*:*

  • Configuration 30:
  • cpe:/o:amd:ryzen_5_5600x_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_5600x:-:*:*:*:*:*:*:*

  • Configuration 31:
  • cpe:/o:amd:ryzen_5_5625c_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_5625c:-:*:*:*:*:*:*:*

  • Configuration 32:
  • cpe:/o:amd:ryzen_5_5625u_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_5625u:-:*:*:*:*:*:*:*

  • Configuration 33:
  • cpe:/o:amd:ryzen_5_5700g_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_5700g:-:*:*:*:*:*:*:*

  • Configuration 34:
  • cpe:/o:amd:ryzen_5_5700ge_firmware:-:*:*:*:*:*:*:*
  • AND
  • cpe:/h:amd:ryzen_5_5700ge:-:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    amd radeon software -
    amd ryzen 3 3100 firmware -
    amd ryzen 3 3100 -
    amd ryzen 3 3300g firmware -
    amd ryzen 3 3300g -
    amd ryzen 3 3300x firmware -
    amd ryzen 3 3300x -
    amd ryzen 3 5400u firmware -
    amd ryzen 3 5400u -
    amd ryzen 9 5900hs firmware -
    amd ryzen 9 5900hs -
    amd ryzen 9 5900hx firmware -
    amd ryzen 9 5900hx -
    amd ryzen 9 5980hs firmware -
    amd ryzen 9 5980hs -
    amd ryzen 9 5980hx firmware -
    amd ryzen 9 5980hx -
    amd ryzen 3 5125c firmware -
    amd ryzen 3 5125c -
    amd ryzen 3 5425c firmware -
    amd ryzen 3 5425c -
    amd ryzen 7 3700x firmware -
    amd ryzen 7 3700x -
    amd ryzen 9 3900x firmware -
    amd ryzen 9 3900x -
    amd ryzen 9 3950x firmware -
    amd ryzen 9 3950x -
    amd ryzen 7 3800x firmware -
    amd ryzen 7 3800x -
    amd ryzen 3 5425u firmware -
    amd ryzen 3 5425u -
    amd ryzen 5 3400g firmware -
    amd ryzen 5 3400g -
    amd ryzen 7 5800h firmware -
    amd ryzen 7 5800h -
    amd ryzen 7 5800hs firmware -
    amd ryzen 7 5800hs -
    amd ryzen 7 5800u firmware -
    amd ryzen 7 5800u -
    amd ryzen 7 5825c firmware -
    amd ryzen 7 5825c -
    amd ryzen 7 5825u firmware -
    amd ryzen 7 5825u -
    amd ryzen 5 3450g firmware -
    amd ryzen 5 3450g -
    amd ryzen 5 3600 firmware -
    amd ryzen 5 3600 -
    amd ryzen 5 3600x firmware -
    amd ryzen 5 3600x -
    amd ryzen 5 5560u firmware -
    amd ryzen 5 5560u -
    amd ryzen 5 5600h firmware -
    amd ryzen 5 5600h -
    amd ryzen 5 5600u firmware -
    amd ryzen 5 5600u -
    amd ryzen 5 5600hs firmware -
    amd ryzen 5 5600hs -
    amd ryzen 5 5600x firmware -
    amd ryzen 5 5600x -
    amd ryzen 5 5625c firmware -
    amd ryzen 5 5625c -
    amd ryzen 5 5625u firmware -
    amd ryzen 5 5625u -
    amd ryzen 5 5700g firmware -
    amd ryzen 5 5700g -
    amd ryzen 5 5700ge firmware -
    amd ryzen 5 5700ge -