7.8

CVE-2021-26369

A malicious or compromised UApp or ABL may be used by an attacker to send a malformed system call to the bootloader, resulting in out-of-bounds memory accesses.

Data is provided by the National Vulnerability Database (NVD)
AmdRadeon Software Version-
AmdAthlon 3050ge Firmware Version-
   AmdAthlon 3050ge Version-
AmdAthlon 3150g Firmware Version-
   AmdAthlon 3150g Version-
AmdAthlon 3150ge Firmware Version-
   AmdAthlon 3150ge Version-
AmdRyzen 3 2200u Firmware Version-
   AmdRyzen 3 2200u Version-
AmdRyzen 3 2300u Firmware Version-
   AmdRyzen 3 2300u Version-
AmdRyzen 3 3100 Firmware Version-
   AmdRyzen 3 3100 Version-
AmdRyzen 3 3300g Firmware Version-
   AmdRyzen 3 3300g Version-
AmdRyzen 3 3300x Firmware Version-
   AmdRyzen 3 3300x Version-
AmdRyzen 3 5125c Firmware Version-
   AmdRyzen 3 5125c Version-
AmdRyzen 3 5400u Firmware Version-
   AmdRyzen 3 5400u Version-
AmdRyzen 3 5425c Firmware Version-
   AmdRyzen 3 5425c Version-
AmdRyzen 3 5425u Firmware Version-
   AmdRyzen 3 5425u Version-
AmdRyzen 5 2500u Firmware Version-
   AmdRyzen 5 2500u Version-
AmdRyzen 5 2600 Firmware Version-
   AmdRyzen 5 2600 Version-
AmdRyzen 5 2600h Firmware Version-
   AmdRyzen 5 2600h Version-
AmdRyzen 5 2600x Firmware Version-
   AmdRyzen 5 2600x Version-
AmdRyzen 5 3400g Firmware Version-
   AmdRyzen 5 3400g Version-
AmdRyzen 5 3450g Firmware Version-
   AmdRyzen 5 3450g Version-
AmdRyzen 5 3600 Firmware Version-
   AmdRyzen 5 3600 Version-
AmdRyzen 5 3600x Firmware Version-
   AmdRyzen 5 3600x Version-
AmdRyzen 5 5600h Firmware Version-
   AmdRyzen 5 5600h Version-
AmdRyzen 5 5600hs Firmware Version-
   AmdRyzen 5 5600hs Version-
AmdRyzen 5 5600u Firmware Version-
   AmdRyzen 5 5600u Version-
AmdRyzen 5 5600x Firmware Version-
   AmdRyzen 5 5600x Version-
AmdRyzen 5 5625c Firmware Version-
   AmdRyzen 5 5625c Version-
AmdRyzen 5 5625u Firmware Version-
   AmdRyzen 5 5625u Version-
AmdRyzen 5 5700g Firmware Version-
   AmdRyzen 5 5700g Version-
AmdRyzen 5 5700ge Firmware Version-
   AmdRyzen 5 5700ge Version-
AmdRyzen 7 2700 Firmware Version-
   AmdRyzen 7 2700 Version-
AmdRyzen 7 2700u Firmware Version-
   AmdRyzen 7 2700u Version-
AmdRyzen 7 2700x Firmware Version-
   AmdRyzen 7 2700x Version-
AmdRyzen 7 2800h Firmware Version-
   AmdRyzen 7 2800h Version-
AmdRyzen 7 3700x Firmware Version-
   AmdRyzen 7 3700x Version-
AmdRyzen 7 3800x Firmware Version-
   AmdRyzen 7 3800x Version-
AmdRyzen 7 5800h Firmware Version-
   AmdRyzen 7 5800h Version-
AmdRyzen 7 5800hs Firmware Version-
   AmdRyzen 7 5800hs Version-
AmdRyzen 7 5800u Firmware Version-
   AmdRyzen 7 5800u Version-
AmdRyzen 7 5825c Firmware Version-
   AmdRyzen 7 5825c Version-
AmdRyzen 7 5825u Firmware Version-
   AmdRyzen 7 5825u Version-
AmdRyzen 9 3900x Firmware Version-
   AmdRyzen 9 3900x Version-
AmdRyzen 9 3950x Firmware Version-
   AmdRyzen 9 3950x Version-
AmdRyzen 9 5900hs Firmware Version-
   AmdRyzen 9 5900hs Version-
AmdRyzen 9 5900hx Firmware Version-
   AmdRyzen 9 5900hx Version-
AmdRyzen 9 5980hs Firmware Version-
   AmdRyzen 9 5980hs Version-
AmdRyzen 9 5980hx Firmware Version-
   AmdRyzen 9 5980hx Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.14% 0.343
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 4.6 3.9 6.4
AV:L/AC:L/Au:N/C:P/I:P/A:P
CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer

The product performs operations on a memory buffer, but it reads from or writes to a memory location outside the buffer's intended boundary. This may result in read or write operations on unexpected memory locations that could be linked to other variables, data structures, or internal program data.