Back to Database
Status published
Medium
CVE-2021-26377
Insufficient parameter validation while allocating process space in the Trusted...
Vulnerability Description
Insufficient parameter validation while allocating process space in the Trusted OS (TOS) may allow for a malicious userspace process to trigger an integer overflow, leading to a potential denial of service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-26377
Credits & Attribution
No credits recorded in the NVD database.
References
More from AMD
View All →CVE-2025-66664
Insufficient parameter sanitization in AMD Secure Processor (ASP) TEE SOC...
Medium
4.6
CVE-2025-66660
Insufficient parameter sanitization in TEE SOC Driver could allow an...
Low
1.8
CVE-2025-62628
Unsafe OpenSSL initialization within some AMD optional tools may allow...
High
7
CVE-2025-62627
An untrusted pointer dereference in the ionic cloud driver for...
High
7.2
CVE-2025-62626
Improper handling of insufficient entropy in the AMD CPUs could...
High
7.2
Affected Vendor
Affected Software
AMD Ryzen™ 5000 Series Processors with Radeon™ Graphics, AMD Ryzen™ Threadripper™ 3000 Series Processors, AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors, AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ Threadripper™ PRO 5000 WX-Series Processors, AMD Ryzen™ 5000 Series Desktop Processors, AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 3000 Series Desktop Processors, AMD Ryzen™ 7030 Series Mobile processors with Radeon™ Graphics, AMD Ryzen™ 4000 Series Desktop Processors, AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics, AMD Ryzen™ 6000 Series Processors with Radeon™ Graphics, AMD Ryzen™ Embedded R1000 Series Processors, AMD Ryzen™ Embedded R2000 Series Processors, AMD Ryzen™ Embedded 5000 Series Processors, AMD Ryzen™ Embedded V1000 Series Processors, AMD Ryzen™ Embedded V2000 Series Processors, AMD Ryzen™ Embedded V3000 Series Processors, AMD Radeon™ RX 5000 Series Graphics Products, AMD Radeon™ PRO W5000 Series Graphics Products, AMD Radeon™ RX 6000 Series Graphics Products, AMD Radeon™ PRO W6000 Series Graphics Products, AMD Radeon™ Instinct™ MI25 Graphics Products, AMD Radeon™ PRO V520 Graphics Products, AMD Radeon™ PRO V620 Graphics Products
Vulnerable Versions:
CezannePI-FP6 1.0.0.8, CastlePeakPI-SP3r3 1.0.0.7, CastlePeakWSPI-sWRX8 1.0.0.9, ChagallWSPI-sWRX8 1.0.0.2, ComboAM4v2 PI 1.2.0.5, PicassoPI-FP5 1.0.0.E, PollockPI-FT5 1.0.0.4, ComboAM4PI 1.0.0.9/ ComboAM4 V2 PI 1.2.0.8, RenoirPI-FP6 1.0.0.8, ComboAM4 V2 PI 1.2.0.8, RembrandtPI-FP7_0.0.8.0 RC1, EmbeddedPI-FP5_1.2.0.A, EmbeddedR2KPI-FP5_1.0.0.2, EmbAM4PI 1.0.0.2, EmbeddedPI-FP6_1.0.0.6, EmbeddedPI-FP7r2_1000, AMD Software: Adrenalin Edition 24.7.1 (24.10.29.01), AMD Software: PRO Edition 24.Q2 (24.10.20), Contact your AMD Customer Engineering representative
Timeline
Official Publish:
September 6th, 2025
Last Modified:
September 8th, 2025
Added to House:
July 21st, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H