Junglewise Threat Intelligence

CVE-2021-26380: AMD Trusted OS driver integer overflow memory access

CVE-2021-26380 · Severity: info · CVSS 1.8 · Published 2026-05-15

Vendors: Amd.

Executive brief

A security vulnerability exists in certain AMD software components responsible for managing secure operations. If an attacker has already compromised a high-privilege driver, they could potentially access restricted areas of system memory. This could lead to a loss of data integrity, though the attack requires significant existing access to the system.

Technical details

This vulnerability is characterized as an integer overflow (CWE-190) within an AMD Trusted OS (TOS) driver. An attacker who has already compromised a high-privilege driver can issue a malformed call to trigger out-of-bounds memory access. The attack vector is local and requires high privileges (PR:H) and high complexity (AC:H), limiting the practical exploitability. Successful exploitation results in a loss of integrity by allowing access to memory ranges outside of the driver's intended scope. AMD has referenced this in security bulletins AMD-SB-4017 and AMD-SB-6027.

Affected products

  • AMD Trusted OS (TOS) Driver

Timeline

  • 2026-05-15: advisory: NVD publication date

References