Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-13176 Improper validation of destination address in SVC_LOAD_FW_IMAGE_BY_INSTANCE and SVC_LOAD_BINARY_BY_ATTRIB in a malicious UApp or ABL may allow an attacker to overwrite arbitrary bootloader memory with SPI ROM contents resulting in a loss of integrity and availability.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2024-09-16T22:20:14.838Z

Reserved: 2021-01-29T00:00:00

Link: CVE-2021-26370

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2022-05-10T19:15:08.813

Modified: 2024-11-21T05:56:13.870

Link: CVE-2021-26370

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses