Back to search
CVE-2021-26398
Published: Jan 10, 2023
Modified: Apr 9, 2025
PUBLISHED
Description
Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.
| Vendor | Product | Versions |
|---|---|---|
AMD | 1st Gen EPYC | affected various |
AMD | 2nd Gen EPYC | affected Various |
AMD | 3rd Gen EPYC | affected various |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now