CVE-2021-26311

Summary

CVECVE-2021-26311
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2021-05-13 12:15:00 UTC
Updated2021-05-25 14:49:00 UTC
DescriptionIn the AMD SEV/SEV-ES feature, memory can be rearranged in the guest address space that is not detected by the attestation mechanism which could be used by a malicious hypervisor to potentially lead to arbitrary code execution within the guest VM if a malicious administrator has access to compromise the server hypervisor.

Risk And Classification

Problem Types: CWE-77

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Amd Epyc 7232p - All All All
Hardware Amd Epyc 7251 - All All All
Hardware Amd Epyc 7252 - All All All
Hardware Amd Epyc 7261 - All All All
Hardware Amd Epyc 7262 - All All All
Hardware Amd Epyc 7272 - All All All
Hardware Amd Epyc 7281 - All All All
Hardware Amd Epyc 7282 - All All All
Hardware Amd Epyc 72f3 - All All All
Hardware Amd Epyc 7301 - All All All
Hardware Amd Epyc 7302 - All All All
Hardware Amd Epyc 7302p - All All All
Hardware Amd Epyc 7313 - All All All
Hardware Amd Epyc 7313p - All All All
Hardware Amd Epyc 7343 - All All All
Hardware Amd Epyc 7351 - All All All
Hardware Amd Epyc 7351p - All All All
Hardware Amd Epyc 7352 - All All All
Hardware Amd Epyc 7371 - All All All
Hardware Amd Epyc 73f3 - All All All
Hardware Amd Epyc 7401 - All All All
Hardware Amd Epyc 7401p - All All All
Hardware Amd Epyc 7402 - All All All
Hardware Amd Epyc 7402p - All All All
Hardware Amd Epyc 7413 - All All All
Hardware Amd Epyc 7443 - All All All
Hardware Amd Epyc 7443p - All All All
Hardware Amd Epyc 7451 - All All All
Hardware Amd Epyc 7452 - All All All
Hardware Amd Epyc 7453 - All All All
Hardware Amd Epyc 74f3 - All All All
Hardware Amd Epyc 7501 - All All All
Hardware Amd Epyc 7502 - All All All
Hardware Amd Epyc 7502p - All All All
Hardware Amd Epyc 7513 - All All All
Hardware Amd Epyc 7532 - All All All
Hardware Amd Epyc 7542 - All All All
Hardware Amd Epyc 7543 - All All All
Hardware Amd Epyc 7543p - All All All
Hardware Amd Epyc 7551 - All All All
Hardware Amd Epyc 7551p - All All All
Hardware Amd Epyc 7552 - All All All
Hardware Amd Epyc 75f3 - All All All
Hardware Amd Epyc 7601 - All All All
Hardware Amd Epyc 7642 - All All All
Hardware Amd Epyc 7643 - All All All
Hardware Amd Epyc 7662 - All All All
Hardware Amd Epyc 7663 - All All All
Hardware Amd Epyc 7702 - All All All
Hardware Amd Epyc 7702p - All All All
Hardware Amd Epyc 7713 - All All All
Hardware Amd Epyc 7713p - All All All
Hardware Amd Epyc 7742 - All All All
Hardware Amd Epyc 7763 - All All All
Hardware Amd Epyc 7f32 - All All All
Hardware Amd Epyc 7f52 - All All All
Hardware Amd Epyc 7f72 - All All All
Hardware Amd Epyc 7h12 - All All All
Hardware Amd Epyc Embedded 3101 - All All All
Hardware Amd Epyc Embedded 3151 - All All All
Hardware Amd Epyc Embedded 3201 - All All All
Hardware Amd Epyc Embedded 3251 - All All All
Hardware Amd Epyc Embedded 3255 - All All All
Hardware Amd Epyc Embedded 3351 - All All All
Hardware Amd Epyc Embedded 3451 - All All All

References

ReferenceSourceLinkTags
www.amd.com/en/corporate/product-security/bulletin/amd-sb-1004 MISC www.amd.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report