CVE-2021-26367

MEDIUM
Published Aug 13, 2024 Modified Dec 12, 2024

Description

A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability.

Is your site exposed to CVE-2021-26367?

Run a free security scan — no signup, results in seconds.

CVSS v3.1 Score

5.7
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H

Affected Products

Vendor Product
amd radeon_software
amd radeon_rx_6300m
amd radeon_rx_6400
amd radeon_rx_6450m
amd radeon_rx_6500_xt
amd radeon_rx_6500m
amd radeon_rx_6550m
amd radeon_rx_6550s
amd radeon_rx_6600
amd radeon_rx_6600_xt
amd radeon_rx_6600m
amd radeon_rx_6600s
amd radeon_rx_6650_xt
amd radeon_rx_6650m
amd radeon_rx_6650m_xt
amd radeon_rx_6700
amd radeon_rx_6700_xt
amd radeon_rx_6700m
amd radeon_rx_6700s
amd radeon_rx_6750_gre
amd radeon_rx_6750_xt
amd radeon_rx_6800
amd radeon_rx_6800_xt
amd radeon_rx_6800m
amd radeon_rx_6800s
amd radeon_rx_6850m_xt
amd radeon_rx_6900_xt
amd radeon_rx_6950_xt
amd radeon_software
amd radeon_pro_w6300
amd radeon_pro_w6400
amd radeon_pro_w6600
amd radeon_pro_w6800
amd ryzen_9_5980hx_firmware
amd ryzen_9_5980hx
amd ryzen_3_3300u_firmware
amd ryzen_3_3300u
amd ryzen_3_3350u_firmware
amd ryzen_3_3350u
amd ryzen_5_3450u_firmware
amd ryzen_5_3450u
amd ryzen_5_3500u_firmware
amd ryzen_5_3500u
amd ryzen_5_3500c_firmware
amd ryzen_5_3500c
amd ryzen_5_3550h_firmware
amd ryzen_5_3550h
amd ryzen_5_3580u_firmware
amd ryzen_5_3580u
amd ryzen_7_3700u_firmware
amd ryzen_7_3700u
amd ryzen_7_3700c_firmware
amd ryzen_7_3700c
amd ryzen_7_3750h_firmware
amd ryzen_7_3750h
amd ryzen_7_3780u_firmware
amd ryzen_7_3780u
amd athlon_gold_3150c_firmware
amd athlon_gold_3150c
amd athlon_gold_3150u_firmware
amd athlon_gold_3150u
amd athlon_pro_3145b_firmware
amd athlon_pro_3145b
amd athlon_silver_3050c_firmware
amd athlon_silver_3050c
amd athlon_silver_3050u_firmware
amd athlon_silver_3050u
amd athlon_pro_3045b_firmware
amd athlon_pro_3045b
amd athlon_silver_3050e_firmware
amd athlon_silver_3050e
amd athlon_gold_pro_3150g_firmware
amd athlon_gold_pro_3150g
amd athlon_gold_3150g_firmware
amd athlon_gold_3150g
amd athlon_gold_pro_3150ge_firmware
amd athlon_gold_pro_3150ge
amd athlon_pro_300ge_firmware
amd athlon_pro_300ge
amd ryzen_3_4300ge_firmware
amd ryzen_3_4300ge
amd ryzen_5_4600ge_firmware
amd ryzen_5_4600ge
amd ryzen_7_4700ge_firmware
amd ryzen_7_4700ge
amd ryzen_3_4300g_firmware
amd ryzen_3_4300g
amd ryzen_5_4600g_firmware
amd ryzen_5_4600g
amd ryzen_7_4700g_firmware
amd ryzen_7_4700g
amd ryzen_3_5300ge_firmware
amd ryzen_3_5300ge
amd ryzen_3_5300g_firmware
amd ryzen_3_5300g
amd ryzen_5_5600ge_firmware
amd ryzen_5_5600ge
amd ryzen_5_5600g_firmware
amd ryzen_5_5600g
amd ryzen_7_5700ge_firmware
amd ryzen_7_5700ge
amd ryzen_7_5700g_firmware
amd ryzen_7_5700g

References

Frequently Asked Questions

What is CVE-2021-26367? +
A malicious attacker in x86 can misconfigure the Trusted Memory Regions (TMRs), which may allow the attacker to set an arbitrary address range for the TMR, potentially leading to a loss of integrity and availability. It has a CVSS v3.1 base score of 5.7 (MEDIUM).
How severe is CVE-2021-26367? +
CVE-2021-26367 has a CVSS v3.1 score of 5.7 out of 10, rated MEDIUM. This is a medium-severity vulnerability that should be remediated as part of regular maintenance.
What products are affected by CVE-2021-26367? +
CVE-2021-26367 affects products from amd, specifically: athlon_gold_3150c, athlon_gold_3150c_firmware, athlon_gold_3150g, athlon_gold_3150g_firmware, athlon_gold_3150u, athlon_gold_3150u_firmware, athlon_gold_pro_3150g, athlon_gold_pro_3150g_firmware, athlon_gold_pro_3150ge, athlon_gold_pro_3150ge_firmware, athlon_pro_300ge, athlon_pro_300ge_firmware, athlon_pro_3045b, athlon_pro_3045b_firmware, athlon_pro_3145b, athlon_pro_3145b_firmware, athlon_silver_3050c, athlon_silver_3050c_firmware, athlon_silver_3050e, athlon_silver_3050e_firmware, athlon_silver_3050u, athlon_silver_3050u_firmware, radeon_pro_w6300, radeon_pro_w6400, radeon_pro_w6600, radeon_pro_w6800, radeon_rx_6300m, radeon_rx_6400, radeon_rx_6450m, radeon_rx_6500_xt, radeon_rx_6500m, radeon_rx_6550m, radeon_rx_6550s, radeon_rx_6600, radeon_rx_6600_xt, radeon_rx_6600m, radeon_rx_6600s, radeon_rx_6650_xt, radeon_rx_6650m, radeon_rx_6650m_xt, radeon_rx_6700, radeon_rx_6700_xt, radeon_rx_6700m, radeon_rx_6700s, radeon_rx_6750_gre, radeon_rx_6750_xt, radeon_rx_6800, radeon_rx_6800_xt, radeon_rx_6800m, radeon_rx_6800s, radeon_rx_6850m_xt, radeon_rx_6900_xt, radeon_rx_6950_xt, radeon_software, ryzen_3_3300u, ryzen_3_3300u_firmware, ryzen_3_3350u, ryzen_3_3350u_firmware, ryzen_3_4300g, ryzen_3_4300g_firmware, ryzen_3_4300ge, ryzen_3_4300ge_firmware, ryzen_3_5300g, ryzen_3_5300g_firmware, ryzen_3_5300ge, ryzen_3_5300ge_firmware, ryzen_5_3450u, ryzen_5_3450u_firmware, ryzen_5_3500c, ryzen_5_3500c_firmware, ryzen_5_3500u, ryzen_5_3500u_firmware, ryzen_5_3550h, ryzen_5_3550h_firmware, ryzen_5_3580u, ryzen_5_3580u_firmware, ryzen_5_4600g, ryzen_5_4600g_firmware, ryzen_5_4600ge, ryzen_5_4600ge_firmware, ryzen_5_5600g, ryzen_5_5600g_firmware, ryzen_5_5600ge, ryzen_5_5600ge_firmware, ryzen_7_3700c, ryzen_7_3700c_firmware, ryzen_7_3700u, ryzen_7_3700u_firmware, ryzen_7_3750h, ryzen_7_3750h_firmware, ryzen_7_3780u, ryzen_7_3780u_firmware, ryzen_7_4700g, ryzen_7_4700g_firmware, ryzen_7_4700ge, ryzen_7_4700ge_firmware, ryzen_7_5700g, ryzen_7_5700g_firmware, ryzen_7_5700ge, ryzen_7_5700ge_firmware, ryzen_9_5980hx, ryzen_9_5980hx_firmware. Check the affected products table above for specific version ranges.
How do I check if I'm vulnerable to CVE-2021-26367? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.

Related Vulnerabilities

Don't wait for an exploit

Scan your website for vulnerabilities like CVE-2021-26367 — free, no signup required.