Breaking Down The New Security Flaws In AMD's Ryzen, EPYC Chips

Update, 3/13/18, 11:10pm PT: We have our original coverage of this vulnerability, and the suspicious circumstances surrounding the release of the information, in our original Report Claims AMD Ryzen, EPYC CPUs Contain 13 Security Flaws (Update) article. This companion article serves as a primer for the individual alleged vulnerabilities.

CTS-Labs, a new "research organization" from Israel that seems to have formed last year, claimed to have discovered four categories of bugs affecting AMD’s Ryzen processors, called Masterkey, Ryzenfall, Fallout, and Chimera. (This is a developing story, and we've reached out to both CTS Labs and AMD about these reported vulnerabilities. We'll share more information as we receive it.)

Latest Videos FromTom's Hardware
Contributor

Lucian Armasu is a Contributing Writer for Tom's Hardware US. He covers software news and the issues surrounding privacy and security.

  • Clamyboy74
    Making articles on a flaw that has little to no credibilty... wow
    Also: "AMD’s disregard for fundamental security principles." @Intel meltdown???
    Reply
  • Clamyboy74
    Oh, and digging more onto their web page and youtube, especially youtube:
    https://i.imgur.com/OkWlIxA.jpg
    Reply
  • derekullo
    I guess they are forcing us back to RISC processors.
    Reply
  • HEXiT
    seriously chimera has a hardware back door? NOT COOL!.
    Reply
  • Willyfisch
    Actual news story:
    CTS partnered with Viceroy to make some whitepapers to short AMD.
    Reply
  • Giroro
    Who paid CTS-Labs to write this report?
    I don't think the report is even worth acknowledging until they either prove how they are funded, or until the flaws are validated by a 3rd party.
    They clearly weren't trying to claim any kind of bug bounty, as they went public without giving AMD a chance to fix it.
    Reply
  • cscott_it
    Brought to you by Viceroy
    Reply
  • Willyfisch
    20790349 said:
    Who paid CTS-Labs to write this report?
    I don't think the report is even worth acknowledging until they either prove how they are funded, or until the flaws are validated by a 3rd party.
    They clearly weren't trying to claim any kind of bug bounty, as they went public without giving AMD a chance to fix it.

    Viceroy Research. They are a very shady short seller company (I don't even know who's behind them, might be just 1 person).
    Look at their other shorts, like the -75% on Pro Sieben.
    They are suggesting AMD's fair value to be at $0 in their very professionally made research paper (irony).
    https://viceroyresearch.files.wordpress.com/2018/03/amd-the-obituary-13-mar-2018.pdf
    Reply
  • akamateau
    What is amazing is how every online media outlet is reporting on a piece from ONE source that has been in business for 7 months. The research company started up just before the Spectre and Meltdown flaws were released and now we have 13 AMD ONLY flaws and no mention at all about ANY possible Intel or ARM exploits either.

    Tom's Hardware has ZERO Journalistic Integrity.

    https://imgur.com/OkWlIxA

    I am ABSOLUTELY CERTAIN this entire piece is Securities Fraud and Tom's Hardware is a very willing participant. TH did not vet the source nor did they CHECK ANY FACTS.
    Reply
  • HEXiT
    Somehow I doubt this is fake news as some are suggesting here, as AMD would wring them out to their last cent if this report were a fabrication;
    as it will affect their share price, their reputation and consumer confidence in their products.
    Reply