pwshub.com

AMD's update strategy for the Sinkclose vulnerability leaves some processors unprotected

Serving tech enthusiasts for over 25 years.
TechSpot means tech analysis and advice you can trust.

Why it matters: In response to the recently uncovered Sinkclose vulnerability, AMD is rolling out updates for its newer processor models, leaving many consumers unhappy as several relatively recent chips have been excluded. It may be time for a broader discussion on whether tech companies should extend their support for legacy products, especially when they remain popular among users. If nothing else, companies might need to reconsider these policies to maintain consumer trust and brand loyalty.

In light of the recently disclosed Sinkclose vulnerability, AMD is releasing updates to address the issue across several processor families. These updates include all generations of EPYC processors, as well as the latest Threadripper and Ryzen processors.

Older models, such as the Ryzen 1000, 2000, and 3000 series, as well as the Threadripper 1000 and 2000, will not receive updates as they fall outside AMD's software support window. Interestingly, although the Ryzen 9000 and Ryzen AI 300 series processors are newly released, they are not listed for updates, suggesting the vulnerability may have been addressed during manufacturing.

AMD's approach to software support is a standard practice in the tech industry to efficiently manage resources and focus on newer products. Despite this, many consumers are disappointed with AMD's decision, particularly since some affected processors, like the Ryzen 3000 series, are relatively recent and still widely used.

The Sinkclose vulnerability was discovered by IOActive researchers Enrique Nissim and Krzysztof Okupski, who shared their findings at the Def Con conference. The flaw has likely existed undetected for many years, allowing attackers to exploit a highly privileged mode in AMD processors called System Management Mode. This mode is reserved for critical firmware operations, making the flaw particularly dangerous. Exploiting it requires kernel-level access, which is difficult but possible.

AMD says that there is no expected performance impact from the updates, though performance tests are ongoing to fully assess the impact on system performance.

For users whose AMD processors are not receiving a patch for the Sinkclose vulnerability, options are limited. Upgrading to a newer, supported processor is one possibility.

However, before taking that step, conduct a risk assessment of the threat. The Sinkclose vulnerability is more of a concern for high-value targets like governments or large organizations, as exploiting it requires significant system access, which is not typically a concern for average users.

Nonetheless, ensuring that your operating system and all software are up to date is crucial in general, as well as in response to this particular threat. Being vigilant about who has access to your system is also important. Preventing unauthorized access is key, given that exploiting the vulnerability requires kernel-level access.

Source: techspot.com

Related stories
1 month ago - AMD is reportedly planning to increase the Thermal Design Power (TDP) for two of its Zen 5 processors – the newly launched Ryzen 7 9700X and Ryzen 5 9600X – from 65W to 105W. This information comes from hardware leaker Chi11eddog on X,...
3 weeks ago - Recall, Microsoft's delayed AI recording feature for Windows, will be available to beta testers starting in October. The company is still working to address privacy concerns surrounding the technology, which captures all activity on...
1 month ago - An unnamed major European online PC retailer recently informed the French outlet Les Numeriques that it receives approximately four times as many returns of Raptor Lake processors compared to Alder Lake (12th-gen Intel Core). This...
2 weeks ago - AMD has managed to backport the same Ryzen CPU optimizations to the Windows 11 23H2 build via a new optional update in record time. This comes just a week after the company stated it was "collaborating with Microsoft" to rush out those...
1 month ago - Intel's CPU stability issues persist, with a microcode update expected in a few weeks. While TechSpot has covered various angles, hands-on testing remains pending, here's our take so far.Read Entire Article
Other stories
21 minutes ago - Yes, there are still green bubbles — and security compromises that Apple could have avoided.
21 minutes ago - Amazon CEO Andy Jassy shared a message announcing the new return-to-office policy, telling employees they will be expected to be in the office five days a week starting Jan. 2.
21 minutes ago - TikTok’s ban date is still Jan.19. As lawsuits continue to play out, here is what to know about challenges, the law and what you should know as a user.
27 minutes ago - Eyes on everyone: From cops to the public AI is on the verge of ushering in a new era of mass surveillance, says Oracle cofounder Larry Ellison, and his juggernaut is rip-roaring, ready to serve as the technological backbone for such AI...
27 minutes ago - Collection of 50 new '80s-era game concepts brims with originality, care, and joy.