Bug 2133519 (CVE-2021-26360) - CVE-2021-26360 hw: amd: Unauthorized modifications of the security configuration of the SOC registers
Summary: CVE-2021-26360 hw: amd: Unauthorized modifications of the security configura...
Keywords:
Status: CLOSED NOTABUG
Alias: CVE-2021-26360
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On:
Blocks: 2133020
TreeView+ depends on / blocked
 
Reported: 2022-10-10 17:01 UTC by Rohit Keshri
Modified: 2023-01-27 14:22 UTC (History)
39 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2023-01-27 14:22:52 UTC
Embargoed:


Attachments (Terms of Use)

Description Rohit Keshri 2022-10-10 17:01:06 UTC
An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processor’s encrypted memory contents which may lead to arbitrary code execution in ASP.

Refer:
https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1029

Comment 3 Product Security DevOps Team 2023-01-27 14:22:48 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):

https://access.redhat.com/security/cve/cve-2021-26360


Note You need to log in before you can comment on or make changes to this bug.