Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 12 sources · 6 days · First seen · Last updated
AMD processor security vulnerabilities and patches
Overview
AMD has addressed several high-severity security vulnerabilities affecting its processor architectures through kernel and firmware updates.
Initially, the Linux Kernel 7.1.7 release introduced a patch to harden the Safe-RET mitigation on AMD Zen 1-through-Zen 4 processors. This fix, authored by an AMD engineer, aimed to prevent local attackers from injecting timed interrupts into the return-stack protection sequence, addressing a Spectre-class flaw that could leak kernel memory.
Subsequently, AMD addressed two critical vulnerabilities, CVE-2026-6726 and CVE-2026-6727, affecting the Trusted Platform Module (TPM) 2.0 implementation. These flaws, which carry CVSS scores of 8.5 and 8.3, impact a wide range of hardware including Ryzen desktop CPUs from the 3000 to 9000 series, Threadripper, Epyc, and Ryzen AI processors. The vulnerabilities involve out-of-bounds memory reads and RSA OAEP timing side-channels that could allow attackers to obtain fake TPM credentials or expose encrypted data.
Security researchers have noted that these TPM flaws could allow a local attacker with elevated privileges to extract sensitive data or bypass authentication. AMD has released firmware fixes via AGESA updates, with motherboard manufacturers distributing these through BIOS updates for AM4 and AM5 platforms.
Entities
Greg Kroah‑Hartman · Linux kernel · Trusted Computing Group · University of Birmingham · Advanced Micro Devices, Inc.
Timeline
-
2 days ago
[TECHNOLOGY] 7 sourcesAMD and Windows 11 face major security vulnerabilitiesAMD faces critical TPM vulnerabilities affecting Ryzen processors, while researchers reveal a “Download More RAM” attack that bypasses Windows 11 security via manipulated RAM configuration data.
-
8 days ago
[TECHNOLOGY] 6 sourcesAMD Zen Safe RET Vulnerability Fixed in Linux Kernel 7.1.7Linux Kernel 7.1.7 patches a Spectre‑class Safe‑RET vulnerability on AMD Zen 1‑4 CPUs, authored by Borislav Petkov, preventing local interrupt‑injection attacks.
Sources
borncity.com · chiccheinformatiche.com · donanimhaber.com · geeknetic.es · ginjfo.com · iguru.gr · ilsoftware.it · infoguerra.com.br · it-boltwise.de · linuxcompatible.org · sempreupdate.com.br · theregister.co.uk
This summary has been updated 1 time: see revision history