Nixpkgs Security Tracker

Login with GitHub

Suggestion detail

Untriaged
Permalink CVE-2024-21981
5.7 MEDIUM
  • CVSS version: 3.1
  • Attack vector (AV): LOCAL
  • Attack complexity (AC): HIGH
  • Privileges required (PR): HIGH
  • User interaction (UI): NONE
  • Scope (S): UNCHANGED
  • Confidentiality impact (C): HIGH
  • Integrity impact (I): HIGH
  • Availability impact (A): NONE
created 6 months ago
Improper key usage control in AMD Secure Processor (ASP) may …

Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity.

Affected products

PI
  • ==various
epyc
  • *
ryzen
  • *
athlon
  • *
AMD EPYC™ 7002 Series Processors
  • ==various
AMD EPYC™ 7003 Series Processors
  • ==various
AMD EPYC™ Embedded 3000 Series Processors
  • ==various
AMD EPYC™ Embedded 7002 Series Processors
  • ==various
AMD EPYC™ Embedded 7003 Series Processors
  • ==various
AMD Ryzen™ 3000 Series Desktop Processors
  • ==various
AMD Ryzen™ 5000 Series Desktop Processors
  • ==various
AMD Ryzen™ Embedded 5000 Series Processors
  • ==various
AMD Ryzen™ Embedded R1000 Series Processors
  • ==various
AMD Ryzen™ Embedded R2000 Series Processors
  • ==various
AMD Ryzen™ Embedded V1000 Series Processors
  • ==various
AMD Ryzen™ Threadripper™ PRO 5000WX Processors
  • ==various
AMD Ryzen™ Threadripper™ 3000 Series Processors
  • ==various
AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors
  • ==various
AMD Ryzen™ 3000 Series Mobile Processor with Radeon™ Graphics
  • ==various
AMD Ryzen™ 5000 Series Desktop Processor with Radeon™ Graphics
  • ==various
AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics
  • ==various
AMD Athlon™ 3000 Series Desktop Processors with Radeon™ Graphics
  • ==various
AMD Athlon™ 3000 Series Mobile Processors with Radeon™ Graphics
  • ==various

Matching in nixpkgs

pkgs.spoofdpi

Simple and fast anti-censorship tool written in Go

  • nixos-unstable -