Description
Insufficient bounds checking in ASP may allow an attacker to issue a system call from a compromised ABL which may cause arbitrary memory values to be initialized to zero, potentially leading to a loss of integrity.
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected products
- AMD / 2nd Gen AMD EPYC™ Processorsvarious – various
- AMD / 2nd Gen AMD Ryzen™ Threadripper™ Processors “Colfax”various – various
- AMD / 3rd Gen AMD EPYC™ Processorsvarious – various
- AMD / 3rd Gen AMD Ryzen™ Threadripper™ Processors “Castle Peak” HEDTvarious – various
- AMD / AMD Ryzen™ 5000 Series Desktop Processors “Vermeer” AM4various – various
- AMD / Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Dali”/”Dali” ULPvarious – various
- AMD / Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics “Pollock”various – various
- AMD / Ryzen™ 2000 Series Desktop Processors “Pinnacle Ridge”various – various
- AMD / Ryzen™ 2000 series Desktop Processors “Raven Ridge” AM4various – various
- AMD / Ryzen™ 2000 Series Mobile Processors “Raven Ridge” FP5various – various
- AMD / Ryzen™ 3000 Series Desktop Processors “Matisse” AM4various – various
- AMD / Ryzen™ 3000 Series Mobile processor, 2nd Gen AMD Ryzen™ Mobile Processors with Radeon™ Graphics “Picasso”various – various
- AMD / Ryzen™ 3000 Series Mobile Processors with Radeon™ Graphics “Renoir”various – various
- AMD / Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics “Cezanne” AM4Various – Various
- AMD / Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics “Cezanne”various – various
- AMD / Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics “Lucienne”various – various
- AMD / Ryzen™ Threadripper™ PRO Processors “Castle Peak” WSvarious – various
- AMD / Ryzen™ Threadripper™ PRO Processors “Chagall” WSvarious – various