CVE-2021-26388

MEDIUM

AMD Epyc 7232p Firmware < romepi-sp3_1.0.0.d - Out-of-Bounds Read

Title source: rule
STIX 2.1

Description

Improper validation of the BIOS directory may allow for searches to read beyond the directory table copy in RAM, exposing out of bounds memory contents, resulting in a potential denial of service.

References (2)

Core 2

Scores

CVSS v3 5.5
EPSS 0.0004
EPSS Percentile 11.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-125
Status published
Products (50)
amd/epyc_7232p_firmware < romepi-sp3_1.0.0.d
amd/epyc_7252_firmware < romepi-sp3_1.0.0.d
amd/epyc_7262_firmware < romepi-sp3_1.0.0.d
amd/epyc_7272_firmware < romepi-sp3_1.0.0.d
amd/epyc_7282_firmware < romepi-sp3_1.0.0.d
amd/epyc_72f3_firmware < milanpi-sp3_1.0.0.7
amd/epyc_7302_firmware < romepi-sp3_1.0.0.d
amd/epyc_7302p_firmware < romepi-sp3_1.0.0.d
amd/epyc_7313p_firmware < milanpi-sp3_1.0.0.7
amd/epyc_7343_firmware < milanpi-sp3_1.0.0.7
... and 40 more
Published May 11, 2022
Tracked Since Feb 18, 2026