SMU
by AMD
CVEs (13)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-26379 | Cri | 0.64 | 9.8 | 0.01 | May 9, 2023 | Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation. | ||
| CVE-2021-26331 | Hig | 0.51 | 7.8 | 0.00 | Nov 16, 2021 | AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution. | ||
| CVE-2021-46764 | Hig | 0.49 | 7.5 | 0.01 | May 9, 2023 | Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service. | ||
| CVE-2021-46763 | Hig | 0.49 | 7.5 | 0.00 | May 9, 2023 | Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity. | ||
| CVE-2023-20531 | Hig | 0.49 | 7.5 | 0.01 | Jan 11, 2023 | Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service. | ||
| CVE-2023-20530 | Hig | 0.49 | 7.5 | 0.01 | Jan 11, 2023 | Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service. | ||
| CVE-2023-20529 | Hig | 0.49 | 7.5 | 0.01 | Jan 11, 2023 | Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service. | ||
| CVE-2023-20532 | Med | 0.34 | 5.3 | 0.01 | Jan 11, 2023 | Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service. | ||
| CVE-2021-26350 | Med | 0.31 | 4.7 | 0.00 | May 11, 2022 | A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service. | ||
| CVE-2023-31365 | Low | 0.25 | 3.9 | 0.00 | Sep 6, 2025 | An integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reserved dRAM area resulting in loss of integrity or availability. | ||
| CVE-2021-46762 | Low | 0.25 | 3.9 | 0.00 | May 9, 2023 | Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service. | ||
| CVE-2023-20528 | Low | 0.16 | 2.4 | 0.00 | Jan 11, 2023 | Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality. | ||
| CVE-2023-31304 | Low | 0.15 | 2.3 | 0.00 | Aug 13, 2024 | Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to modify the PCIe® lane count and speed, potentially leading to a loss of availability. |
- risk 0.64cvss 9.8epss 0.01
Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.
- risk 0.51cvss 7.8epss 0.00
AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.
- risk 0.49cvss 7.5epss 0.01
Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.00
Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.
- risk 0.49cvss 7.5epss 0.01
Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.01
Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.
- risk 0.49cvss 7.5epss 0.01
Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.
- risk 0.34cvss 5.3epss 0.01
Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.
- risk 0.31cvss 4.7epss 0.00
A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.
- risk 0.25cvss 3.9epss 0.00
An integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reserved dRAM area resulting in loss of integrity or availability.
- risk 0.25cvss 3.9epss 0.00
Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.
- risk 0.16cvss 2.4epss 0.00
Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.
- risk 0.15cvss 2.3epss 0.00
Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF) to modify the PCIe® lane count and speed, potentially leading to a loss of availability.