AMD's AI ambitions face a new barrier as the firm's China-compliant Instinct MI309 AI GPU may not receive approval from the US Commerce Secretary Department.
15.02.2024 - 10:54 / wccftech.com / Muhammad Zuhair
AMD has disclosed new BIOS-side vulnerabilities across all of its Zen CPU generations, which has particularly impacted the SPI connection, compromising security.
The emergence of vulnerabilities across CPU architectures isn't surprising, but this time, AMD has apparently discovered something much bigger, impacting a more extensive consumer base, and the severity of it is listed as "high" this time as well. Moreover, the discovered vulnerabilities enter from your motherboard's BIOS as well; hence, the matter is indeed sensitive, and according to AMD, the consequences of the mentioned include the "trigger" of arbitrary codes and much more.
Moving into the specifics, AMD mentions that the vulnerability is broken down into four different compromises, and it relies on "messing up" with your SPI interface, which can lead to malicious activities such as denial of service, execution of arbitrary codes, and the bypass of your system's integrity. Team Red has described the vulnerabilities in multiple CVEs, and you can view their findings below to have an idea of how costly it can be:
CVE Severity CVE Description CVE-2023-20576 High Insufficient Verification of Data Authenticity in AGESA may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation. CVE-2023-20577 High A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution. CVE-2023-20579 High Improper Access Control in the AMD SPI protection feature may allow a user with Ring0 (kernel mode) privileged access to bypass protections potentially resulting in loss of integrity and availability. CVE-2023-20587 High Improper Access Control in System Management Mode (SMM) may allow attackers access to the SPI flash, potentially leading to arbitrary code execution.However, the good thing is that to stay safe from the vulnerabilities mentioned above, AMD has advised its consumers to update to the latest AGESA versions, which the firm has already pushed out.
The new versions target mitigations for all AMD Ryzen CPU lineups, along with AMD's EPYC, Threadripper, and Embedded series as well, which shows that as long as you have the correct AGESA version loaded into your systems, it won't be much of a huge deal. However, particular SKUs, such as the Ryzen 4000G and 5000G APUs, haven't received mitigation patches in their respective motherboards, which
AMD's AI ambitions face a new barrier as the firm's China-compliant Instinct MI309 AI GPU may not receive approval from the US Commerce Secretary Department.
NVIDIA has banned the use of CUDA libraries on other platforms like AMD & Intel, as the firm adds a new warning with CUDA's EULA.
V-Color has announced its brand new OC R-DIMM Octo-Kit DDR5 memory for AMD WRX90 platform which features up to 768 GB capacities & 7200 MT/s speeds.
The Jurassic World 4 title might finally be confirmed by a new rumor as the next installment in the popular franchise roars toward theaters next year.
Can you feel it? Can you? If so, you’re likely a gamer who wants to get their hands on Final Fantasy VII Rebirth the moment it comes out on Thursday. That’s a key thing to state: it comes out on Thursday! After years of waiting after the release of the first remake title, the sequel is almost here, and gamers can’t wait to see what the title is like in full. To their credit, Square Enix has been doing its job with hyping up the game to nearly insane levels. They even released a massive number of review codes so that nearly everyone would sing the game’s praises, and it worked!
Microsoft is planning to unveil its DirectX DirectSR "Super Resolution" tech at GDC 2024 which is being worked on with AMD & NVIDIA.
Nearly thirteen years after its original launch, The Elder Scrolls V: Skyrim still sees many interesting mods developed by the community.
NVIDIA is "ironically" expected to run out of Blackwell B100 GPUs supply ahead of its respective launch, as the firm anticipates vast demand.
AMD is expected to launch a refreshed MI300 AI accelerator with HBM3E memory this year followed by the Instinct MI400 in 2025.
Intel's CEO Pat Gelsinger has revealed the firm's intention to enter the "custom chip" business, catering to every type of client, including AMD.
AMD's CEO, Dr. Lisa Su, will deliver the opening keynote of Computex 2024 where we'll get to hear about the upcoming technologies for PC & AI segments.
The makers of the Fallout London mod have announced many impressive details about the game, which we'll recap later in this article, but the latest news from the final progress video is that none other than Neil Newbon will lend his voice acting chops to the game.