Security features bypass in 3rd Gen AMD EPYC Processors - CVE-2021-26349
Published: May 26, 2022
Vulnerability identifier: #VU63688
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2021-26349
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: AMD
Affected software:
3rd Gen AMD EPYC Processors
3rd Gen AMD EPYC Processors
Detailed vulnerability description
The vulnerability allows an attacker to compromise the guest OS.
The vulnerability exists due to failure to assign a new report ID to an imported guest. This can result in an SEV-SNP guest VM being tricked into trusting a dishonest Migration Agent (MA).
How to mitigate CVE-2021-26349
Install updates from vendor's website.