CVE-2021-26383
BaseFortify
Publication date: 2025-09-06
Last updated on: 2025-09-08
Assigner: Advanced Micro Devices Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amd | athlon | * |
| amd | embedded_processor | * |
| amd | radeon_pro_w7000 | * |
| amd | ryzen | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2021-26383 is a high-severity vulnerability in AMD's Trusted Execution Environment (TEE) caused by insufficient bounds checking. An attacker who has already compromised userspace can invoke a command with malformed arguments, leading to out-of-bounds memory access. This can result in loss of system integrity or availability. [1, 2]
How can this vulnerability impact me? :
This vulnerability can impact you by causing loss of integrity and availability of the affected system. An attacker with local high privileges can exploit this flaw to cause out-of-bounds memory access, potentially disrupting system operations or compromising system integrity. [1, 2]
What immediate steps should I take to mitigate this vulnerability?
To mitigate CVE-2021-26383, you should update the Platform Initialization (PI) firmware to versions starting from EmbeddedPI-FP6 1.0.0.0 or later for affected AMD Ryzen Embedded V2000 Series processors. Additionally, update AMD software and drivers to the versions that include fixes for this vulnerability, such as ROCm 6.4, Radeon Software Adrenalin Edition 23.2.1, Radeon Software for Linux 25.10.1, and AMD Software PRO Edition 23.Q1, depending on your hardware. These updates address the insufficient bounds checking issue in the AMD Trusted Execution Environment (TEE) and help prevent out-of-bounds memory access that could lead to loss of integrity or availability. [1, 2]