← Back to CVE List
Vulnerability Intelligence Report

CVE-2021-26365

Certain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potentially limited leakage of information about out-of-bounds memory contents.

No Active Exploit Signals
CVSS Base Score
8.2
HIGH
Exploitability:3.9
Impact Score:4.3
EPSS Probability:0.57%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-125 ↗CWE-125 Out-of-bounds Read

Affected Products & Versions

Vendor Product Affected Versions
AMD Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4 various (affected)
AMD Ryzen™ 5000 Series Desktop processor with Radeon™ Graphics “Cezanne” AM4 various (affected)
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Dali”/”Dali” ULP various (affected)
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Pollock” various (affected)
AMD Ryzen™ 2000 Series Mobile Processors “Raven Ridge” FP5 various (affected)
AMD Ryzen™ 3000 Series Mobile processor, 2nd Gen AMD Ryzen™ Mobile Processors with Radeon™ Graphics “Picasso” various (affected)
AMD Ryzen™ 3000 Series Mobile Processors with Radeon™ Graphics “Renoir” various (affected)
AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics “Lucienne” various (affected)
AMD Ryzen™ 5000 Series Mobile processors with Radeon™ Graphics “Cezanne” various (affected)
AMD Ryzen™ 6000 Series Mobile Processors "Rembrandt" various (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
0.571%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdvanced Micro Devices Inc. · Vendor · USA
Reserved2021-01-29T21:24:26
Published2023-05-09T18:58:57
Patch Date2023-05-09
Last Updated2025-01-28T15:47:24

LINK COPIED TO CLIPBOARD