LiveActive security incident?Get immediate response
CVE Record

CVE-2021-26339: A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to tr...

A bug in AMD CPU’s core logic may allow for an attacker, using specific code from an unprivileged VM, to trigger a CPU core hang resulting in a potential denial of service. AMD believes the specific code includes a specific x86 instruction sequence that would not be generated by compilers.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

CVE-2021-26339 is an AMD CPU logic flaw that may let code running inside an unprivileged virtual machine hang a CPU core, causing denial of service. The public bundle does not provide CVSS, detailed affected versions, or confirmed exploitation evidence.

Executive priority

Treat this as a virtualization availability risk, not a data-theft issue based on current sources. Prioritize cloud, hosting, lab, and shared VM environments first because a guest-triggered CPU hang can disrupt service availability.

Technical view

AMD describes a core-logic bug triggered by a specific x86 instruction sequence from an unprivileged VM. The sequence is reportedly not compiler-generated. Affected product families include various AMD EPYC, Ryzen, and Athlon processors. The disclosed impact is CPU core hang and potential denial of service.

Likely exposure

Primary exposure is virtualized infrastructure using affected AMD EPYC processors, especially where untrusted tenants or workloads can run VM code. Ryzen and Athlon systems are also listed, but the source bundle does not specify exact versions or deployment conditions.

Exploitation context

The bundle does not show CISA KEV listing or cited evidence of active exploitation. Exploitation appears to require intentionally crafted low-level instruction behavior from inside an unprivileged VM, not ordinary compiled application code.

Researcher notes

Evidence is limited to AMD and CVE records in the provided bundle. No CVSS, CWE, exact model list, proof-of-concept status, or patch matrix is included here. Avoid assuming broader impact beyond potential CPU core denial of service.

Mitigation direction

  • Review AMD SB-1027 and SB-1028 for processor-specific guidance.
  • Prioritize AMD EPYC virtualization hosts with untrusted or multi-tenant workloads.
  • Apply vendor-approved BIOS, firmware, or microcode updates where AMD identifies them.
  • Limit untrusted VM workloads until applicable vendor guidance is confirmed.

Validation and detection

  • Inventory AMD EPYC, Ryzen, and Athlon systems in scope.
  • Map CPU models against AMD SB-1027 and SB-1028 affected-product details.
  • Confirm hypervisors and host firmware are at vendor-recommended levels.
  • Check whether any untrusted VM tenancy exists on affected AMD hosts.
Prepared
Confidence
medium
Sources
4

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2021-26339 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
3Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
AMDEPYC™ ProcessorsvariousListed
AMDRyzen™ SeriesvariousListed
AMDAthlon™ SeriesvariousListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.