NVD Vulnerability Detail
Search Exploit, PoC
CVE-2021-26382
Summary

An attacker with root account privileges can load any legitimately signed firmware image into the Audio Co-Processor (ACP,) irrespective of the respective signing key being declared as usable for authenticating an ACP firmware image, potentially resulting in a denial of service.

Publication Date July 15, 2022, 5:15 a.m.
Registration Date July 15, 2022, 10 a.m.
Last Update Nov. 21, 2024, 2:56 p.m.
CVSS3.1 : MEDIUM
スコア 4.4
Vector CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
攻撃元区分(AV) ローカル
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR)
利用者の関与(UI) 不要
影響の想定範囲(S) 変更なし
機密性への影響(C) なし
完全性への影響(I) なし
可用性への影響(A)
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_5700g_firmware:*:*:*:*:*:*:*:* comboam4_v2_pi_1.2.0.6c
execution environment
1 cpe:2.3:h:amd:ryzen_7_5700g:-:*:*:*:*:*:*:*
Configuration2 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_5700ge_firmware:*:*:*:*:*:*:*:* comboam4_v2_pi_1.2.0.6c
execution environment
1 cpe:2.3:h:amd:ryzen_7_5700ge:-:*:*:*:*:*:*:*
Configuration3 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_5600g_firmware:*:*:*:*:*:*:*:* comboam4_v2_pi_1.2.0.6c
execution environment
1 cpe:2.3:h:amd:ryzen_5_5600g:-:*:*:*:*:*:*:*
Configuration4 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_5600ge_firmware:*:*:*:*:*:*:*:* comboam4_v2_pi_1.2.0.6c
execution environment
1 cpe:2.3:h:amd:ryzen_5_5600ge:-:*:*:*:*:*:*:*
Configuration5 or higher or less more than less than
cpe:2.3:o:amd:ryzen_3_5300g_firmware:*:*:*:*:*:*:*:* comboam4_v2_pi_1.2.0.6c
execution environment
1 cpe:2.3:h:amd:ryzen_3_5300g:-:*:*:*:*:*:*:*
Configuration6 or higher or less more than less than
cpe:2.3:o:amd:ryzen_3_5300ge_firmware:*:*:*:*:*:*:*:* comboam4_v2_pi_1.2.0.6c
execution environment
1 cpe:2.3:h:amd:ryzen_3_5300ge:-:*:*:*:*:*:*:*
Configuration7 or higher or less more than less than
cpe:2.3:o:amd:ryzen_9_5980hx_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_9_5980hx:-:*:*:*:*:*:*:*
Configuration8 or higher or less more than less than
cpe:2.3:o:amd:ryzen_9_5980hs_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_9_5980hs:-:*:*:*:*:*:*:*
Configuration9 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_5825u_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_7_5825u:-:*:*:*:*:*:*:*
Configuration10 or higher or less more than less than
cpe:2.3:o:amd:ryzen_9_5900hx_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_9_5900hx:-:*:*:*:*:*:*:*
Configuration11 or higher or less more than less than
cpe:2.3:o:amd:ryzen_9_5900hs_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_9_5900hs:-:*:*:*:*:*:*:*
Configuration12 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_5825c_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_7_5825c:-:*:*:*:*:*:*:*
Configuration13 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_5800h_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_7_5800h:-:*:*:*:*:*:*:*
Configuration14 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_5625u_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_5_5625u:-:*:*:*:*:*:*:*
Configuration15 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_5800hs_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_7_5800hs:-:*:*:*:*:*:*:*
Configuration16 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_5625c_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_5_5625c:-:*:*:*:*:*:*:*
Configuration17 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_5600h_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_5_5600h:-:*:*:*:*:*:*:*
Configuration18 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_5600hs_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_5_5600hs:-:*:*:*:*:*:*:*
Configuration19 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_5800u_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_7_5800u:-:*:*:*:*:*:*:*
Configuration20 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_5600u_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_5_5600u:-:*:*:*:*:*:*:*
Configuration21 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_5560u_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_5_5560u:-:*:*:*:*:*:*:*
Configuration22 or higher or less more than less than
cpe:2.3:o:amd:ryzen_3_5425u_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_3_5425u:-:*:*:*:*:*:*:*
Configuration23 or higher or less more than less than
cpe:2.3:o:amd:ryzen_3_5425c_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_3_5425c:-:*:*:*:*:*:*:*
Configuration24 or higher or less more than less than
cpe:2.3:o:amd:ryzen_3_5400u_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_3_5400u:-:*:*:*:*:*:*:*
Configuration25 or higher or less more than less than
cpe:2.3:o:amd:ryzen_3_5125c_firmware:*:*:*:*:*:*:*:* cezannepi-fp6_1.0.0.9
execution environment
1 cpe:2.3:h:amd:ryzen_3_5125c:-:*:*:*:*:*:*:*
Configuration26 or higher or less more than less than
cpe:2.3:o:amd:ryzen_3_3200u_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_3_3200u:-:*:*:*:*:*:*:*
Configuration27 or higher or less more than less than
cpe:2.3:o:amd:ryzen_3_3250u_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_3_3250u:-:*:*:*:*:*:*:*
Configuration28 or higher or less more than less than
cpe:2.3:o:amd:ryzen_3_3300u_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_3_3300u:-:*:*:*:*:*:*:*
Configuration29 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_3500u_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_5_3500u:-:*:*:*:*:*:*:*
Configuration30 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_3550h_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_5_3550h:-:*:*:*:*:*:*:*
Configuration31 or higher or less more than less than
cpe:2.3:o:amd:ryzen_5_3580u_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_5_3580u:-:*:*:*:*:*:*:*
Configuration32 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_3700u_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_7_3700u:-:*:*:*:*:*:*:*
Configuration33 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_pro_3700u_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_7_pro_3700u:-:*:*:*:*:*:*:*
Configuration34 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_3750h_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_7_3750h:-:*:*:*:*:*:*:*
Configuration35 or higher or less more than less than
cpe:2.3:o:amd:ryzen_7_3780u_firmware:*:*:*:*:*:*:*:* renoirpi-fp6_1.0.0.7
execution environment
1 cpe:2.3:h:amd:ryzen_7_3780u:-:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List

JVN Vulnerability Information
複数の Advanced Micro Devices (AMD) 製品における脆弱性
Title 複数の Advanced Micro Devices (AMD) 製品における脆弱性
Summary

ryzen 7 5700g ファームウェア、ryzen 7 5700ge ファームウェア、ryzen 5 5600g ファームウェア等複数の Advanced Micro Devices (AMD) 製品には、不特定の脆弱性が存在します。

Possible impacts サービス運用妨害 (DoS) 状態にされる可能性があります。
Solution

ベンダアドバイザリまたはパッチ情報が公開されています。参考情報を参照して適切な対策を実施してください。

Publication Date Jan. 29, 2021, midnight
Registration Date Sept. 11, 2023, 5:19 p.m.
Last Update Sept. 11, 2023, 5:19 p.m.
Affected System
Advanced Micro Devices (AMD)
ryzen 3 5300g ファームウェア comboam4_v2_pi_1.2.0.6c 未満
ryzen 3 5300ge ファームウェア comboam4_v2_pi_1.2.0.6c 未満
ryzen 5 5600g ファームウェア comboam4_v2_pi_1.2.0.6c 未満
ryzen 5 5600ge ファームウェア comboam4_v2_pi_1.2.0.6c 未満
ryzen 5 5600h ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 5 5600hs ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 5 5600u ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 5 5625c ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 5 5625u ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 7 5700g ファームウェア comboam4_v2_pi_1.2.0.6c 未満
ryzen 7 5700ge ファームウェア comboam4_v2_pi_1.2.0.6c 未満
ryzen 7 5800h ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 7 5800hs ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 7 5800u ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 7 5825c ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 7 5825u ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 9 5900hs ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 9 5900hx ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 9 5980hs ファームウェア cezannepi-fp6_1.0.0.9 未満
ryzen 9 5980hx ファームウェア cezannepi-fp6_1.0.0.9 未満
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
その他
Change Log
No Changed Details Date of change
1 [2023年09月11日]
  掲載
Sept. 11, 2023, 5:19 p.m.