CVE-2021-26408

HIGH

AMD EPYC 7001 and 7002 Firmware - Insufficient Validation of Elliptic Curve Points in SEV-Legacy Firmware

Title source: llm
STIX 2.1

Description

Insufficient validation of elliptic curve points in SEV-legacy firmware may compromise SEV-legacy guest migration potentially resulting in loss of guest's integrity or confidentiality.

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0013
EPSS Percentile 31.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

Status published
Products (38)
amd/epyc_7001_firmware < naplespi-sp3_1.0.0.g
amd/epyc_7002_firmware < romepi-sp3_1.0.0.c
amd/epyc_7232p_firmware < romepi-sp3_1.0.0.c
amd/epyc_7251_firmware < naplespi-sp3_1.0.0.g
amd/epyc_7252_firmware < romepi-sp3_1.0.0.c
amd/epyc_7262_firmware < romepi-sp3_1.0.0.c
amd/epyc_7272_firmware < romepi-sp3_1.0.0.c
amd/epyc_7281_firmware < naplespi-sp3_1.0.0.g
amd/epyc_7282_firmware < romepi-sp3_1.0.0.c
amd/epyc_7301_firmware < naplespi-sp3_1.0.0.g
... and 28 more
Published May 10, 2022
Tracked Since Feb 18, 2026