AMD hit with 31 new vulnerabilities to start 2023, affecting Ryzen & EPYC CPU lines
The company has created numerous mitigations to alleviate the exposed processors and has also disclosed a report from the company in cooperation with teams from three top companies — Apple, Google, and Oracle. The company also announced several AGESA variants listed in the update (AGESA code is found when building the system’s BIOS and UEFI code). Due to the vulnerability’s nature, the AGESA changes have been delivered to OEMs, and any patching will depend on each vendor to release it as soon as possible. It would be wise for consumers to visit the vendor’s official website to find out if there is a new update waiting for download rather than waiting for the company to roll it out later. AMD Processors vulnerable to this new attack include Ryzen models for desktops, HEDT, Pro, and mobile CPU series. There is a single vulnerability labeled as “high severity,” while two others are less extreme but still important to patch. All exposures are attacked through the BIOS and ASP bootloader (also known as the AMD Secure Processor bootloader). AMD CPU series that are vulnerable are:
Ryzen 2000 (Pinnacle Ridge) series processors Ryzen 2000 APUs Ryzen 5000 APUs AMD Threadripper 2000 HEDT and Pro server processor series AMD Threadripper 3000 HEDT and Pro server processor series Ryzen 2000 series mobile processors Ryzen 3000 series mobile processors Ryzen 5000 series mobile processors Ryzen 6000 series mobile processors Athlon 3000 series mobile processors
Twenty-eight AMD vulnerabilities have been discovered affecting EPYC processors, with four models labeled with a “high severity” by the company. The three of high severity can have arbitrary code that can be executed through attack vectors in numerous areas. Also, one of the three listed has an additional exploit that permits writing data to specific sections leading to data loss. Other research teams found another fifteen vulnerabilities with lower severity and nine with minor severity. Because of the large number of affected processors exploited, the company chose to disclose this recent vulnerability list that would typically be published in May and November each year and make sure that mitigations were prepared for release. Other vulnerabilities within AMD products include a variant of Hertzbleed, another that acts similarly to the Meltdown exploit, and one called “Take A Way.” DESKTOP HIGH END DESKTOP WORKSTATION MOBILE - AMD Athlon Series MOBILE - AMD Ryzen Series News Sources: Tom’s Hardware, AMD Client Vulnerabilities – January 2023, AMD Server Vulnerabilities – January 2023