Security features bypass in AMD products - CVE-2021-26382
Published: May 26, 2022
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to missing verification of the signing key when processing ACP firmware images. A local privileged user can load any legitimately signed firmware image into the Audio
Co-Processor (ACP) irrespective of the respective signing key being
declared as usable for authenticating an ACP firmware image, and perform a denial of service (DoS) attack.
Affected software
AMD Ryzen 3000 Series Mobile processor with Radeon graphics
AMD Ryzen 5000 Series Mobile processor with Radeon graphics