Permissions, Privileges, and Access Controls in AMD products - CVE-2021-26363

 

Permissions, Privileges, and Access Controls in AMD products - CVE-2021-26363

Published: May 26, 2022


Vulnerability identifier: #VU63732
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-26363
CWE-ID: CWE-264
Exploitation vector: Local access
Exploit availability: No public exploit available
Vendor: AMD
Affected software:
AMD Ryzen 5000 Series Desktop processor with Radeon graphics
AMD Ryzen 3000 Series Mobile processor with Radeon graphics
AMD Ryzen 5000 Series Mobile processor with Radeon graphics

Detailed vulnerability description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due to improper access restrictions. A malicious or compromised UApp or ABL can modify value used by ASP for its reserved DRAM to one outside of the fenced area and gain access to sensitive information.


How to mitigate CVE-2021-26363

Install updates from vendor's website.

Sources