CVE-2021-26350
- EPSS 0.1%
- Veröffentlicht 11.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:11
A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.
CVE-2021-26364
- EPSS 0.07%
- Veröffentlicht 11.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:12
Insufficient bounds checking in an SMU mailbox register could allow an attacker to potentially read outside of the SRAM address range which could result in an exception handling leading to a potential denial of service.
CVE-2021-26373
- EPSS 0.12%
- Veröffentlicht 11.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:14
Insufficient bound checks in the System Management Unit (SMU) may result in a system voltage malfunction that could result in denial of resources and/or possibly denial of service.
CVE-2021-26375
- EPSS 0.08%
- Veröffentlicht 11.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:14
Insufficient General Purpose IO (GPIO) bounds check in System Management Unit (SMU) may result in access/updates from/to invalid address space that could result in denial of service.
CVE-2021-26376
- EPSS 0.12%
- Veröffentlicht 11.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:15
Insufficient checks in System Management Unit (SMU) FeatureConfig may result in reenabling features potentially resulting in denial of resources and/or denial of service.
CVE-2021-26378
- EPSS 0.12%
- Veröffentlicht 11.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:15
Insufficient bound checks in the System Management Unit (SMU) may result in access to an invalid address space that could result in denial of service.
CVE-2021-26388
- EPSS 0.12%
- Veröffentlicht 11.05.2022 17:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:16
Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.
CVE-2021-46771
- EPSS 0.1%
- Veröffentlicht 10.05.2022 19:15:09
- Zuletzt bearbeitet 21.11.2024 06:34:41
Insufficient validation of addresses in AMD Secure Processor (ASP) firmware system call may potentially lead to arbitrary code execution by a compromised user application.
CVE-2021-26370
- EPSS 0.13%
- Veröffentlicht 10.05.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:13
Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity...
CVE-2021-26353
- EPSS 0.13%
- Veröffentlicht 10.05.2022 19:15:08
- Zuletzt bearbeitet 21.11.2024 05:56:11
Failure to validate inputs in SMM may allow an attacker to create a mishandled error leaving the DRTM UApp in a partially initialized state potentially resulting in loss of memory integrity.