AMD Responds To CPU Security Flaw Report

AMD has finally issued a full response to CTS Labs’ report that Ryzen and EPYC processors contain a total of 13 security flaws. Here’s the short version of the chipmakers’ response:

Exploitation of the vulnerabilities requires admin accessThe vulnerabilities have to do with firmware and chipsets, not the x86 architecturePatches are coming in the form of BIOS updates and firmware patches only--no microcode updates are required--via OEMs and ODMsAll issues will be addressed within “weeks,” but we strongly infer that AMD is aiming for 90 days or lessThere is no expected performance impact

Latest Videos FromTom's Hardware

Seth Colaner previously served as News Director at Tom's Hardware. He covered technology news, focusing on keyboards, virtual reality, and wearables.

  • redgarl
    2 weeks... not 2 years like CTS-Labs was saying. We can now categorize these guys as clowns... and toms as an unreliable journalism source. At least anandtech and gamernexus did real journalism.

    https://www.youtube.com/watch?v=ZZ7H1WTqaeo
    Reply
  • clutchc
    So, what's the bottom line for the consumer? Update the board's BIOS when one comes available? Or will the patch come directly from AMD in the form of a download?

    Also, is this something older AMD processors are affected by? Phenoms, Athlons, FX?
    Reply
  • redgarl
    Also, these are Asmedia flaws... Intel, you are affected to.
    Reply
  • Druidsmark
    I for one am kinda glad CTS Labs did it this way as it forces AMD to react and fix the problems sooner.

    As my Asus computer is over to years old, I don't know if I will see an update for my M32BF A10-7800, hopefully they will update my motherboard once AMD start releasing the patches for these security vulnerabilities.
    Reply
  • Alerean
    You have nothing to worry about...someone who has your administrative privileges is going to have control of your system without these exploits anyway...
    Reply
  • Ilya__
    20812420 said:
    You have nothing to worry about...someone who has your administrative privileges is going to have control of your system without these exploits anyway...

    Exactly, if someone has your credentials you are screwed already. Open Chrome, then Cntrl+H...you are done for XD
    Reply
  • Gam3r01
    20812318 said:
    2 weeks... not 2 years like CTS-Labs was saying. We can now categorize these guys as clowns... and toms as an unreliable journalism source. At least anandtech and gamernexus did real journalism.

    https://www.youtube.com/watch?v=ZZ7H1WTqaeo

    Just to be clear, you are aware that TH and anandtech are sister sites right?
    Reply
  • SkyBill40
    20812319 said:
    Also, is this something older AMD processors are affected by? Phenoms, Athlons, FX?

    Seeing that CTS has made no mention of the older lines and focused solely on Ryzen for what still amounts to rather sketchy targeting based on the upcoming refresh, I doubt it. While it is still a possibility, nothing is assured in any sense. While I applaud AMD for taking prompt and effective counters to the reported issues, I still feel this to be a stock shorting move and little else. It's all too convenient and stinks no matter how much they want to cover it up.
    Reply
  • nobspls
    20812318 said:
    ..... and toms as an unreliable journalism source. ....

    Really skewering Tom's so quickly. What has Tom's done? Fool me once shame on you right? CTS fooled all sorts of people. Tom's is eager to report the news no doubt, and may have been quick on the trigger, but I'm pretty sure Tom's not falling for CTS shenanigans any time soon I would hope.

    Reply
  • clutchc
    20812538 said:
    20812319 said:
    Also, is this something older AMD processors are affected by? Phenoms, Athlons, FX?

    Seeing that CTS has made no mention of the older lines and focused solely on Ryzen for what still amounts to rather sketchy targeting based on the upcoming refresh, I doubt it. While it is still a possibility, nothing is assured in any sense. While I applaud AMD for taking prompt and effective counters to the reported issues, I still feel this to be a stock shorting move and little else. It's all too convenient and stinks no matter how much they want to cover it up.

    It does sound fishy since Intel is suffering right now with spectre and meltdown
    Reply