ZeroHour

CVE-2021-26342

CVSS 3.1
3.3 low
EPSS
<1%p12
Published
()
Modified
Description

In SEV guest VMs, the CPU may fail to flush the Translation Lookaside Buffer (TLB) following a particular sequence of operations that includes creation of a new virtual machine control block (VMCB). The failure to flush the TLB may cause the microcode to use stale TLB translations which may allow for disclosure of SEV guest memory contents. Users of SEV-ES/SEV-SNP guest VMs are not impacted by this vulnerability.

Vendors
amd
Products
epyc 7763 firmware, epyc 7713p firmware, epyc 7713 firmware, epyc 7663 firmware, epyc 7643 firmware, epyc 75f3 firmware, epyc 7543p firmware, epyc 7543 firmware, epyc 7513 firmware, epyc 7453 firmware, epyc 74f3 firmware, epyc 7443p firmware
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.