CVE Published: 10/01/2023 |
CVE Updated: 03/08/2024 |
CVE Year: 2021 Source: AMD |
Vendor: AMD |
Product: 1st Gen EPYC Status : PUBLISHED
CVE-2021-26398 Description
Insufficient input validation in SYS_KEY_DERIVE system call in a compromised user application or ABL may allow an attacker to corrupt ASP (AMD Secure Processor) OS memory which may lead to potential arbitrary code execution.