ZeroHour

CVE-2021-46792

CVSS 3.1
5.9 medium
EPSS
<1%p33
Published
()
Modified
Description

Time-of-check Time-of-use (TOCTOU) in the BIOS2PSP command may allow an attacker with a malicious BIOS to create a race condition causing the ASP bootloader to perform out-of-bounds SRAM reads upon an S3 resume event potentially leading to a denial of service.

Vendors
amd
Products
ryzen 5300g firmware, ryzen 5300ge firmware, ryzen 5500 firmware, ryzen 5600 firmware, ryzen 5600g firmware, ryzen 5600ge firmware, ryzen 5600x firmware, ryzen 5700g firmware, ryzen 5700ge firmware, ryzen 5700x firmware, ryzen 5800 firmware, ryzen 5800x3d firmware
Weakness
CWE-367
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.