Skip to content

Comment on CVE-2021-26333 - Flaw in AMD PSP chipset affects millions of computers

Comments

God I HATE this beneath-the-bottom-of-the-barrel quality enterprise value add shite. And the enterprises that keep paying for them without any idea of just how bad the quality is...

That said...

Don't you have to turn the PSP on (like IME) for it to be vulnerable to exploitation?

The first part of the problem is when a user makes a call to the AMD driver to allocate some uninitialised memory using the AMD PSP
The second problem involves calls to the driver to free up contiguous memory space that has previously been allocated.

Surely (LOL) unprivileged code isn't allowed to make these calls?

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.