Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-26316

Опубликовано: 10 янв. 2023
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.

A flaw was found in hw. Failure to validate the BIOS's communication buffer and communication service may allow an attacker to tamper with the buffer, resulting in potential System Management Mode (SMM) arbitrary code execution.

Меры по смягчению последствий

Please contact AMD for more updates on this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2164357hw: amd: arbitrary code execution in bios due to a fault in communication buffer

EPSS

Процентиль: 30%
0.00109
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
около 3 лет назад

Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.

CVSS3: 7.8
github
около 3 лет назад

Failure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in potential SMM (System Management Mode) arbitrary code execution.

CVSS3: 7.8
fstec
около 3 лет назад

Уязвимость системы BIOS микропрограммного обеспечения процессоров AMD, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 30%
0.00109
Низкий

7.8 High

CVSS3

Уязвимость CVE-2021-26316