CVE-2021-26346

Severity CVSS v4.0:
Pending analysis
Type:
CWE-190 Integer Overflow or Wraparound
Publication date:
11/01/2023
Last modified:
09/04/2025

Description

Failure to validate the integer operand in ASP (AMD Secure Processor) bootloader may allow an attacker to introduce an integer overflow in the L2 directory table in SPI flash resulting in a potential denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:amd:ryzen_3_3100_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3100:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3200g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3200g:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3200u_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3200u:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3250c_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3250c:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3250u_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3250u:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3300g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3300g:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3300u_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_3_3300u:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_3_3300x_firmware:-:*:*:*:*:*:*:*