Time-of-check Time-of-use (TOCTOU) Race Condition in AMD products - CVE-2021-26356
Published: May 9, 2023
Vulnerability identifier: #VU75925
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-26356
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vendor: AMD
Affected software:
1st Gen AMD EPYC Processors
2nd Gen AMD EPYC Processors
3rd Gen AMD EPYC Processors
1st Gen AMD EPYC Processors
2nd Gen AMD EPYC Processors
3rd Gen AMD EPYC Processors
Detailed vulnerability description
The vulnerability allows a local user to gain access to sensitive information.
The vulnerability exists due to a race condition in ASP bootloader. A local user can tamper with the SPI ROM, corrupt S3 data and gain access to sensitive information.
How to mitigate CVE-2021-26356
Install updates from vendor's website.