Improper Syscall Input Validation in AMD Secure Processor (ASP) Enables Kernel Memory Disclosure
CVE-2021-26410 Published on February 10, 2026
Improper syscall input validation in ASP (AMD Secure Processor) may force the kernel into reading syscall parameter values from its own memory space allowing an attacker to infer the contents of the kernel memory leading to potential information disclosure.
Weakness Type
Untrusted Pointer Dereference
The program obtains a value from an untrusted source, converts this value to a pointer, and dereferences the resulting pointer.
Affected Versions
AMD Ryzen™ 5000 Series Desktop Processors with Radeon™ Graphics:- Version ComboAM4v2 PI 1.2.0.5+ iGPU Driver Update is unaffected.
- Version RenoirPI-FP6 1.0.0.8 is unaffected.
- Version CezannePI-FP6 1.0.0.8 is unaffected.
- Version CezannePI-FP6 1.0.0.8 is unaffected.
- Version ComboAM4v2 PI 1.2.0.5 is unaffected.
- Version EmbeddedPI-FP5_1.2.0.A is unaffected.
- Version EmbeddedR2KPI-FP5_1.0.0.2 is unaffected.
- Version EmbeddedPI-FP5_1.2.0.A is unaffected.
- Version EmbeddedPI-FP5_1.2.0.A is unaffected.
- Version EmbeddedPI-FP6_1.0.0.6 is unaffected.
- Version EmbeddedPI-FP7r2_1.0.0.0 is unaffected.
- Version AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10), Radeon Software For Linux (25.10.1) is unaffected.
- Version AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10), Radeon Software For Linux (25.10.1) is unaffected.
- Version AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10), Radeon Software For Linux (25.10.1) is unaffected.
- Version AMD Software: Adrenalin Edition 25.6.1 (25.10.13.01), AMD Software: PRO Edition 25.Q2 (25.10.10), Radeon Software For Linux (25.10.1) is unaffected.
- Version Contact your AMD Customer Engineering representative is unaffected.
- Version Contact your AMD Customer Engineering representative is unaffected.
Exploit Probability
EPSS
0.01%
Percentile
0.52%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.