Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.
History

Wed, 09 Apr 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: AMD

Published:

Updated: 2025-04-09T14:38:06.009Z

Reserved: 2021-01-29T21:24:26.167Z

Link: CVE-2021-26398

cve-icon Vulnrichment

Updated: 2024-08-03T20:26:24.878Z

cve-icon NVD

Status : Modified

Published: 2023-01-11T08:15:11.487

Modified: 2025-04-09T15:15:43.823

Link: CVE-2021-26398

cve-icon Redhat

No data.