← Vulnerability feed

Vulnerability record · CVE-2021-26317 · published 12 May 2022

CVE-2021-26317: Amd radeon software vulnerability

AAmd · Radeon Software

Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.

7.8 CVSS 3.1 High EPSS 0.27% · top 82.2%
7.8CVSS 3.1 base score, v2 7.2
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
74Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Failure to verify the protocol in SMM may allow an attacker to control the protocol and modify SPI flash resulting in a potential arbitrary code execution.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

74 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-26317 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-20586Amd radeon software vulnerabilityA potential vulnerability was reported in Radeon™ Software Crimson ReLive Edition which may allow escalation of privilege. Radeon™ Software Crimson R…EPSS 1.00%8.8CVE-2023-20558Amd ryzen 7 5700g firmware vulnerabilityInsufficient control flow management in AmdCpmOemSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to an escalat…EPSS 0.67%8.8CVE-2023-20559Amd ryzen 7 5700g firmware vulnerabilityInsufficient control flow management in AmdCpmGpioInitSmm may allow a privileged attacker to tamper with the SMM handler potentially leading to escal…EPSS 0.67%8.2CVE-2021-26365Amd ryzen 5 2400g firmware out-of-bounds read vulnerabilityCertain size values in firmware binary headers could trigger out of bounds reads during signature validation, leading to denial of service or potenti…EPSS 0.57%7.8CVE-2024-21937Amd radeon software incorrect default permissions vulnerabilityIncorrect default permissions in the AMD HIP SDK installation directory could allow an attacker to achieve privilege escalation potentially resulting…EPSS 0.26%7.8CVE-2023-20598Amd radeon software improper privilege management vulnerabilityAn improper privilege management in the AMD Radeon™ Graphics driver may allow an authenticated attacker to craft an IOCTL request to gain I/O control…EPSS 0.46%7.8CVE-2021-26316Amd epyc 7h12 firmware improper input validation vulnerabilityFailure to validate the communication buffer and communication service in the BIOS may allow an attacker to tamper with the buffer resulting in poten…EPSS 0.26%7.8CVE-2021-26391Amd enterprise driver improper verification of cryptographic signature vulnerabilityInsufficient verification of multiple header signatures while loading a Trusted Application (TA) may allow an attacker with privileges to gain code e…EPSS 0.18%

Source: NIST National Vulnerability Database (record CVE-2021-26317), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.