Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2021-46795

Опубликовано: 10 янв. 2023
Источник: redhat
CVSS3: 1.9
EPSS Низкий

Описание

A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.

A Time-of-check to time-of-use (TOCTOU) vulnerability exists in hw. This flaw allows an attacker to use a compromised BIOS to cause the trusted execution environment (TEE) operating system to read memory out-of-bounds, potentially resulting in a denial of service.

Меры по смягчению последствий

Please contact AMD for more updates on this flaw.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6kernelNot affected
Red Hat Enterprise Linux 7kernelNot affected
Red Hat Enterprise Linux 7kernel-rtNot affected
Red Hat Enterprise Linux 8kernelNot affected
Red Hat Enterprise Linux 8kernel-rtNot affected
Red Hat Enterprise Linux 9kernelNot affected
Red Hat Enterprise Linux 9kernel-rtNot affected

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=2164382hw: amd: TOCTOU (time-of-check to time-of-use) vulnerability cause memory out of bound results in a denial of service

EPSS

Процентиль: 12%
0.00042
Низкий

1.9 Low

CVSS3

Связанные уязвимости

CVSS3: 4.7
nvd
около 3 лет назад

A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.

CVSS3: 4.7
github
около 3 лет назад

A TOCTOU (time-of-check to time-of-use) vulnerability exists where an attacker may use a compromised BIOS to cause the TEE OS to read memory out of bounds that could potentially result in a denial of service.

EPSS

Процентиль: 12%
0.00042
Низкий

1.9 Low

CVSS3