ZeroHour

CVE-2021-26333

CVSS 3.1
5.5 medium
EPSS
<1%p42
Published
()
Modified
Description

An information disclosure vulnerability exists in AMD Platform Security Processor (PSP) chipset driver. The discretionary access control list (DACL) may allow low privileged users to open a handle and send requests to the driver resulting in a potential data leak from uninitialized physical pages.

Vendors
amd
Products
chipset driver, psp driver
Weakness
CWE-200, CWE-909
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news