• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.
  • The forums have been upgraded with support for dark mode. By default it will follow the setting on your system/browser. You may override it by scrolling to the end of the page and clicking the gears icon.

AMD EPYC Processors Hit by 22 Security Vulnerabilities, Patch is Already Out

AleksandarK

News Editor
Staff member
Joined
Aug 19, 2017
Messages
3,097 (1.09/day)
AMD EPYC class of enterprise processors has gotten infected by as many as 22 different security vulnerabilities. These vulnerabilities range anywhere from medium to high severity, affecting all three generations of AMD EPYC processors. This includes AMD Naples, Rome, and Milan generations, where almost all three are concerned with the whole 22 exploits. There are a few exceptions, and you can find that on AMD's website. However, not all seems to be bad. AMD says that "During security reviews in collaboration with Google, Microsoft, and Oracle, potential vulnerabilities in the AMD Platform Security Processor (PSP), AMD System Management Unit (SMU), AMD Secure Encrypted Virtualization (SEV) and other platform components were discovered and have been mitigated in AMD EPYC AGESA PI packages."

AMD has already shipped new mitigations in the form of AGESA updates, and users should not fear if they keep their firmware up to date. If you or your organization is running on AMD EPYC processors, you should update the firmware to avoid any exploits from happening. The latest updates in question are NaplesPI-SP3_1.0.0.G, RomePI-SP3_1.0.0.C, and MilanPI-SP3_1.0.0.4 AGESA versions, which fix all of 22 security holes.


View at TechPowerUp Main Site
 
Amd still has a long way to go on the software side
The Intel ME has every bit of the same spotty security history.

It's not a brand thing. It's that hardware security is and remains a bad model.
 
The Intel ME has every bit of the same spotty security history.

It's not a brand thing. It's that hardware security is and remains a bad model.

Perhaps another way to re-word it is that anything connected to the internet is simply at risk, and modernity is highly overrated?
 
Perhaps another way to re-word it is that anything connected to the internet is simply at risk, and modernity is highly overrated?
That's oversimplifying it a bit, I feel.
 
I wonder of there was a performance hit, like when Intel ...
 
The SEV also affects Ryzen cpu's? Or they not been patched because it isnt expected use case?
 
Back
Top