VYPR

SMU

by AMD

CVEs (13)

  • CVE-2021-26379CriMay 9, 2023
    risk 0.64cvss 9.8epss 0.01

    Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to a loss of integrity and privilege escalation.

  • CVE-2021-26331HigNov 16, 2021
    risk 0.51cvss 7.8epss 0.00

    AMD System Management Unit (SMU) contains a potential issue where a malicious user may be able to manipulate mailbox entries leading to arbitrary code execution.

  • CVE-2021-46764HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.01

    Improper validation of DRAM addresses in SMU may allow an attacker to overwrite sensitive memory locations within the ASP potentially resulting in a denial of service.

  • CVE-2021-46763HigMay 9, 2023
    risk 0.49cvss 7.5epss 0.00

    Insufficient input validation in the SMU may enable a privileged attacker to write beyond the intended bounds of a shared memory buffer potentially leading to a loss of integrity.

  • CVE-2023-20531HigJan 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient bound checks in the SMU may allow an attacker to update the SRAM from/to address space to an invalid value potentially resulting in a denial of service.

  • CVE-2023-20530HigJan 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient input validation of BIOS mailbox messages in SMU may result in out-of-bounds memory reads potentially resulting in a denial of service.

  • CVE-2023-20529HigJan 11, 2023
    risk 0.49cvss 7.5epss 0.01

    Insufficient bound checks in the SMU may allow an attacker to update the from/to address space to an invalid value potentially resulting in a denial of service.

  • CVE-2023-20532MedJan 11, 2023
    risk 0.34cvss 5.3epss 0.01

    Insufficient input validation in the SMU may allow an attacker to improperly lock resources, potentially resulting in a denial of service.

  • CVE-2021-26350MedMay 11, 2022
    risk 0.31cvss 4.7epss 0.00

    A TOCTOU race condition in SMU may allow for the caller to obtain and manipulate the address of a message port register which may result in a potential denial of service.

  • CVE-2023-31365LowSep 6, 2025
    risk 0.25cvss 3.9epss 0.00

    An integer overflow in the SMU could allow a privileged attacker to potentially write memory beyond the end of the reserved dRAM area resulting in loss of integrity or availability.

  • CVE-2021-46762LowMay 9, 2023
    risk 0.25cvss 3.9epss 0.00

    Insufficient input validation in the SMU may allow an attacker to corrupt SMU SRAM potentially leading to a loss of integrity or denial of service.

  • CVE-2023-20528LowJan 11, 2023
    risk 0.16cvss 2.4epss 0.00

    Insufficient input validation in the SMU may allow a physical attacker to exfiltrate SMU memory contents over the I2C bus potentially leading to a loss of confidentiality.

  • CVE-2023-31304LowAug 13, 2024
    risk 0.15cvss 2.3epss 0.00

    Improper input validation in SMU may allow an attacker with privileges and a compromised physical function (PF)     to modify the PCIe® lane count and speed, potentially leading to a loss of availability.