< Back to situation

[REVISION HISTORY]

AMD processor security vulnerabilities and patches

Updated 1 time since CLSTR started tracking revisions of this situation.

What changed

2026-08-12 22:20 UTC → 2026-08-14 12:03 UTC · added removed

AMD has addressed several high-severity security vulnerabilities affecting its processor architectures through kernel and firmware updates. Initially, the Linux Kernel 7.1.7 release introduced a patch to harden the Safe-RET mitigation on AMD Zen 1-through-Zen 4 processors. This fix, authored by an AMD engineer, aimed to prevent local attackers from injecting timed interrupts into the return-stack protection sequence, addressing a Spectre-class flaw that could leak kernel memory. Subsequently, AMD addressed two critical vulnerabilities, CVE-2026-6726 and CVE-2026-6727, affecting the Trusted Platform Module (TPM) 2.0 implementation. These flaws, which carry CVSS scores of 8.5 and 8.3, impact a wide range of hardware including Ryzen desktop CPUs from the 3000 to 9000 series, Threadripper, Epyc, and Ryzen AI processors. The vulnerabilities involve out-of-bounds memory reads and RSA OAEP timing side-channels that could allow attackers to obtain fake TPM credentials or expose encrypted data. Security researchers have noted that these TPM flaws could allow a local attacker with elevated privileges to extract sensitive data or bypass authentication. AMD has released firmware fixes via AGESA updates, with motherboard manufacturers distributing these through BIOS updates. updates for AM4 and AM5 platforms.

Versions

  1. 2026-08-14 12:03 UTC AMD processor security vulnerabilities and patches
  2. 2026-08-12 22:20 UTC AMD processor security vulnerabilities and patches

Only revisions since CLSTR began indexing content versions appear here. Select a version to see what changed compared to the one before it.