PT-2022-9730 · Amd+1 · Amd Secure Processor+1

Published

2022-05-11

·

Updated

2023-08-08

·

CVE-2021-26347

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions AMD Secure Processor (affected versions not specified)
Description The issue is related to a failure to validate the integer operand in the ASP bootloader, which may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash, resulting in a potential denial of service. Additionally, a time-of-check to time-of-use issue in the System Management Unit may result in a Direct Memory Access to an invalid DRAM address, potentially causing a denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Weakness Enumeration

Related Identifiers

CVE-2021-26347
OPENSUSE-SU-2022_1840-1
OPENSUSE-SU-2022_1923-1
SUSE-SU-2022:1751-1
SUSE-SU-2022:1840-1
SUSE-SU-2022:1846-1
SUSE-SU-2022:1847-1
SUSE-SU-2022:1923-1

Affected Products

Amd Secure Processor
Suse