VYPR
Unrated severityNVD Advisory· Published May 12, 2022· Updated May 5, 2025

CVE-2021-33078

CVE-2021-33078

Description

Race condition within a thread in firmware for some Intel(R) Optane(TM) SSD and Intel(R) SSD DC Products may allow a privileged user to potentially enable denial of service via local access.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A race condition in Intel Optane SSD and SSD DC firmware allows a privileged local attacker to cause denial of service.

Vulnerability

A race condition vulnerability exists in the firmware of certain Intel(R) Optane(TM) SSD and Intel(R) SSD DC products. Specifically, a race condition within a thread can be triggered by a privileged user with local access, leading to denial of service. Affected products and firmware versions are listed in the Intel advisory INTEL-SA-00563 [1].

Exploitation

An attacker must be a privileged user with local access to the system. By initiating concurrent operations that trigger a race condition within the firmware thread, the attacker can cause the solid-state drive to enter an unstable state, resulting in denial of service [1]. No user interaction beyond local system access is required.

Impact

Successful exploitation leads to denial of service for the affected Intel SSD, making the drive unavailable for read/write operations. The confidentiality and integrity of data are not directly compromised, but the availability of storage is impacted [1].

Mitigation

Intel has released firmware updates to address this vulnerability. Users should update their drive firmware to the version specified in INTEL-SA-00563 [1]. There are no known workarounds; updating firmware is the recommended mitigation.

References
  1. INTEL-SA-00563

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.