EVGA

AMD EPYC Processors Hit by 22 Security Vulnerabilities, Patch is Already Out

Author
rjohnson11
EVGA Forum Moderator
  • Total Posts : 85038
  • Reward points : 0
  • Joined: 10/5/2004
  • Location: Netherlands
  • Status: offline
  • Ribbons : 86
Monday, November 15, 2021 11:41 AM (permalink)
https://www.techpowerup.com/288984/amd-epyc-processors-hit-by-22-security-vulnerabilities-patch-is-already-out
 
AMD EPYC class of enterprise processors has gotten infected by as many as 22 different security vulnerabilities. These vulnerabilities range anywhere from medium to high severity, affecting all three generations of AMD EPYC processors. This includes AMD Naples, Rome, and Milan generations, where almost all three are concerned with the whole 22 exploits. There are a few exceptions, and you can find that on AMD's website. However, not all seems to be bad. AMD says that "During security reviews in collaboration with Google, Microsoft, and Oracle, potential vulnerabilities in the AMD Platform Security Processor (PSP), AMD System Management Unit (SMU), AMD Secure Encrypted Virtualization (SEV) and other platform components were discovered and have been mitigated in AMD EPYC AGESA PI packages."

AMD has already shipped new mitigations in the form of AGESA updates, and users should not fear if they keep their firmware up to date. If you or your organization is running on AMD EPYC processors, you should update the firmware to avoid any exploits from happening. The latest updates in question are NaplesPI-SP3_1.0.0.G, RomePI-SP3_1.0.0.C, and MilanPI-SP3_1.0.0.4 AGESA versions, which fix all of 22 security holes.
 
I must say that AMD has patched these vulnerabilities quickly. 

AMD Ryzen 9 7950X,  Corsair Mp700 Pro M.2, 64GB Corsair Dominator Titanium DDR5  X670E Steel Legend, MSI RTX 4090 Associate Code: H5U80QBH6BH0AXF. I am NOT an employee of EVGA

#1

3 Replies Related Threads

    Flint 1760
    Omnipotent Enthusiast
    • Total Posts : 8149
    • Reward points : 0
    • Joined: 4/26/2009
    • Status: offline
    • Ribbons : 45
    Re: AMD EPYC Processors Hit by 22 Security Vulnerabilities, Patch is Already Out Monday, November 15, 2021 11:50 AM (permalink)
    As far as timeline, generally, the problems are discovered, fixed, and the updates released, before a public announcement.


    #2
    Hoggle
    EVGA Forum Moderator
    • Total Posts : 8899
    • Reward points : 0
    • Joined: 10/14/2003
    • Location: Eugene, OR
    • Status: offline
    • Ribbons : 4
    Re: AMD EPYC Processors Hit by 22 Security Vulnerabilities, Patch is Already Out Monday, November 15, 2021 2:46 PM (permalink)
    I agree that they normally would patch and then let people know about the risk after it's been fixed. Right now until the end users apply the firmware update is a time the exploits are most at risk of happening. Seems as though we only hear about an exploit before the patch is when the security exploit happens by hackers and we have it hit major news outlets.

    Use an Associates Code & SAVE 5% - 10% on your purchase. Just click on the associates banner to save, or enter the associates code at checkout on your next purchase. If you choose to use my code I want to personally say "Thank You" for using it. 
     
     
    #3
    Nereus
    Captain Goodvibes
    • Total Posts : 18192
    • Reward points : 0
    • Joined: 4/10/2009
    • Location: Brooklyn, NYC.
    • Status: offline
    • Ribbons : 58
    Re: AMD EPYC Processors Hit by 22 Security Vulnerabilities, Patch is Already Out Tuesday, November 16, 2021 8:00 PM (permalink)
     
    What!? I thought AMD could do no wrong and only Intel had such issues! The horror!   /s
     


      BUILD 1 2   |   MINI-ITX BUILD   |   MODSRIGS $1K WIN   |   HEATWARE 111-0-0 

    #4
    Jump to: