CVE-2021-26393 - CVE House
Back to Database
Status published Medium CVE-2021-26393

Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted...

Vulnerability Description

Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-26393

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

AMD Radeon RX 5000 Series & PRO W5000 Series, AMD Radeon RX 6000 Series & PRO W6000 Series, AMD Ryzen™ Embedded R1000, AMD Ryzen™ Embedded R2000, AMD Ryzen™ Embedded V1000, AMD Ryzen™ Embedded V2000
Vulnerable Versions:
AMD Radeon Software, AMD Radeon Pro Software Enterprise, Enterprise Driver, various

Timeline

Official Publish: November 9th, 2022
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.