CVE-2021-26365
Severity CVSS v4.0:
Pending analysis
Type:
CWE-125
Out-of-bounds Read
Publication date:
09/05/2023
Last modified:
28/01/2025
Description
Certain size values in firmware binary headers<br />
could trigger out of bounds reads during signature validation, leading to<br />
denial of service or potentially limited leakage of information about<br />
out-of-bounds memory contents.<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
<br />
Impact
Base Score 3.x
8.20
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:amd:ryzen_5_2400g_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:ryzen_5_2400g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:ryzen_5_2400ge_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:ryzen_5_2400ge:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:ryzen_3_2200ge_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:ryzen_3_2200ge:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:ryzen_3_2200g_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:ryzen_3_2200g:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:ryzen_3_pro_2100ge_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:ryzen_3_pro_2100ge:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:ryzen_9_5900x_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:ryzen_9_5900x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:ryzen_9_5950x_firmware:-:*:*:*:*:*:*:* | ||
| cpe:2.3:h:amd:ryzen_9_5950x:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:amd:ryzen_9_5900_firmware:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



