AMD has notified its partners and consumers about a number of recently identified transient scheduler exploits that jeopardize the privacy of sensitive data on a number of its chip generations.
Identified during an internal investigation into findings from a Microsoft report titled “Enter, Exit, Page Fault, Leak: Testing Isolation Boundaries for Microarchitectural Leaks,” AMD’s engineers uncovered multiple speculative side-channel vulnerabilities potentially allowing attackers to infer protected data via subtle variations in execution timing.
Medium Severity Vulnerabilities
The vulnerabilities, collectively referenced under AMD-SB-7029, manifest under specific microarchitectural conditions, typically involving speculative execution paths within the processor’s scheduler and memory subsystems.
The flaws are tracked via four CVEs, the most serious of which (CVE-2024-36350 and CVE-2024-36357, both rated 5.6 Medium by CVSS) may let local attackers infer data from prior store operations or the L1D cache, thus breaching privilege boundaries.
Two lesser vulnerabilities (CVE-2024-36348 and CVE-2024-36349, both CVSS-rated 3.8 Low) could enable user processes to speculatively access control registers and TSC_AUX registers, respectively, bypassing certain existing hardware-based protections.
In a technical brief to OEMs and customers, AMD stressed that while not all products are affected, an extensive cross-section spanning multiple generations including EPYC data center processors, Ryzen desktop and mobile CPUs, and Radeon graphics for data center workloads require urgent mitigations.
The company has distributed updated Platform Initialization (PI) firmware versions to OEM partners, with specific minimum firmware releases and corresponding deadlines outlined for each processor family.
In addition to firmware updates, OS-level patches are recommended, and end-users are instructed to consult both their system vendors and operating system providers for the relevant updates.
Among data center solutions, the vulnerabilities chiefly impact Milan, Milan-X, Genoa, Genoa-X, Bergamo, Siena, and the Instinct MI300A GPU platforms, with fixes available or planned via new PI firmware versions and OS patches.
On the client side, affected platforms include Ryzen 5000 and 7000 series desktops as well as mobile Ryzen 6000, 7000, and 8000 series, with remediation timelines generally targeting late 2024 through early 2025. However, AMD clarified that not all vulnerabilities necessitate mitigation for all products.
For instance, the leakage of TSC_AUX and CPU configuration data associated with CVE-2024-36349 and CVE-2024-36348, respectively, is regarded as having negligible risk to sensitive information, and no fixes are planned for these on platforms where the impact is minimal.
Notably, several earlier products (such as the 1st and 2nd Gen EPYC and certain Ryzen 3000/4000/7000 series chips) are either not affected or have been assessed as not requiring a fix due to the limited exploitability and lack of sensitive data exposure.
OS Updates Recommended for Mitigation
AMD’s alert underscores the ongoing challenges posed by transient execution and speculative side-channel attacks in modern high-performance processors.
This class of vulnerability, which rose to prominence following the Spectre and Meltdown discoveries, exploits legitimate architectural optimizations to leak information across isolation boundaries.
AMD’s response highlights the need for coordinated hardware and software updates while reminding users of the importance of timely system and firmware patching for sustained data security.
The company urges all customers enterprises and consumers alike to verify with their system providers regarding firmware rollouts and to apply both BIOS and OS-level updates as soon as they become available.
AMD has also made technical documentation available to OEMs and system integrators detailing mitigation strategies.
System administrators, especially those overseeing data center and cloud environments, should prioritize these updates to ensure continued protection against evolving side-channel threats.
Find this Story Interesting! Follow us on Google News, LinkedIn, and X to Get More Instant updates
