CVE-2021-46760

CRITICAL

AMD Ryzen 3945WX-3995WX Firmware - Out-of-Bounds Memory Access via Malformed System Call

Title source: llm
STIX 2.1

Description

A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory access that may potentially lead to an attacker leaking sensitive information or achieving code execution.

References (1)

Core 1
Core References

Scores

CVSS v3 9.8
EPSS 0.0064
EPSS Percentile 70.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-119 CWE-770
Status published
Products (21)
amd/ryzen_3945wx_firmware castlepeakwspi-swrx8_1.0.0.9
amd/ryzen_3945wx_firmware chagallwspi-swrx8_1.0.0.2
amd/ryzen_3945wx_firmware castlepeakpi-sp3r3_1.0.0.7
amd/ryzen_3955wx_firmware castlepeakwspi-swrx8_1.0.0.9
amd/ryzen_3955wx_firmware chagallwspi-swrx8_1.0.0.2
amd/ryzen_3955wx_firmware castlepeakpi-sp3r3_1.0.0.7
amd/ryzen_3960x_firmware castlepeakwspi-swrx8_1.0.0.9
amd/ryzen_3960x_firmware chagallwspi-swrx8_1.0.0.2
amd/ryzen_3960x_firmware castlepeakpi-sp3r3_1.0.0.7
amd/ryzen_3970x_firmware castlepeakwspi-swrx8_1.0.0.9
... and 11 more
Published May 09, 2023
Tracked Since Feb 18, 2026