TOCTOU Vulnerability in AMD Bootloader Affects SPI ROM Integrity
CVE-2021-26356
7.4HIGH
Key Information:
What is CVE-2021-26356?
A time-of-check to time-of-use (TOCTOU) vulnerability exists in the AMD ASP bootloader. This issue may allow an attacker to manipulate the SPI ROM after reading data into memory, which can lead to potential S3 data corruption and unintended information disclosure.
Affected Version(s)
1st Gen AMD EPYC™ Processors x86 various
2nd Gen AMD EPYC™ Processors x86 various
3rd Gen AMD EPYC™ Processors x86 various