ZeroHour

CVE-2021-46778

CVSS 3.1
5.6 medium
EPSS
<1%p14
Published
()
Modified
Description

Execution unit scheduler contention may lead to a side channel vulnerability found on AMD CPU microarchitectures codenamed “Zen 1”, “Zen 2” and “Zen 3” that use simultaneous multithreading (SMT). By measuring the contention level on scheduler queues an attacker may potentially leak sensitive information.

Vendors
amd
Products
athlon 3050ge firmware, athlon 3150g firmware, athlon 3150ge firmware, epyc 7001 firmware, epyc 7002 firmware, epyc 7003 firmware, epyc 7232p firmware, epyc 7251 firmware, epyc 7252 firmware, epyc 7261 firmware, epyc 7262 firmware, epyc 7272 firmware
Weakness
CWE-203
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N

In the news