Skip to main content

All AMD processors since 2011 have had a security vulnerability

Coming on the heels of recent news that there is an unfixable vulnerability in Intel processors from the last five years, security researchers have identified a vulnerability in AMD processors from the last nine years as well.

A paper by researchers from the Graz University of Technology, first reported on by Tom’s Hardware, describes two attacks, Collide+Probe and Load+Reload, which are a subset of the “Take A Way” vulnerability and are based on a Spectre attack. The vulnerability is found in all AMD processes released between 2011 and 2019, including the Zen microarchitecture.

“We reverse-engineered AMD’s L1D cache way predictor in microarchitectures from 2011 to 2019, resulting in two new attack techniques,” the researchers wrote in the paper. “With Collide+Probe, an attacker can monitor a victim’s memory accesses without knowledge of physical addresses or shared memory when time-sharing a logical core. With Load+Reload, we exploit the way predictor to obtain highly-accurate memory-access traces of victims on the same physical core. While Load+Reload relies on shared memory, it does not invalidate the cache line, allowing stealthier attacks that do not induce any last-level-cache evictions.”

Get your weekly teardown of the tech behind PC gaming
Check your inbox!

Fixes may compromise performance

These are what are called side-channel attacks, which can be deployed by exploiting vulnerabilities in JavaScript via internet browsers such as Google Chrome or Mozilla Firefox. The researchers did suggest both hardware and software fixes which could protect against the vulnerabilities, but these may involve a tradeoff in performance as most Spectre fixes have done. The suggestions include temporarily disabling the processor’s way predictor to prevent attacks, using a keyed mapping function, and flushing the way predictor after use. These fixes are all things that would have to be engineered by AMD, so if you are a regular user then there’s not much you can do except wait to see what security measures AMD will bring in.

This is some controversy around the findings of this paper, as the acknowledgments section includes mention of funding from Intel, first spotted by Hardware Unboxed: “Additional funding was provided by generous gifts from Intel.” This is not unusual in academic research, however, and the lead author responded on Twitter that he discloses the funding Intel provides to some of his students on all of his papers.

Editors' Recommendations

Georgina Torbet
Georgina is the Digital Trends space writer, covering human space exploration, planetary science, and cosmology. She…
Bosch shows off security assistant and souped-up food processor at CES
bosch shows security assistant and food processor at ces 2022bosch process or thermostats 2022 spexor

Bosch, a company known for its high-end appliances, unveiled some new innovations at CES. Perhaps the most interesting device is Spexor, the company's mobile security assistant that's on the lookout for just about anything in the home that might cause harm. The product looks like a cross between an early Google Home speaker and a character you might see on Star Wars.
Spexor senses when something's wrong

The Spexor device uses sensors to detect anything from changes in the temperature to indoor/outdoor air quality and even break-ins. The diminutive unit (4.7-inches tall ) does all this without the use of a camera or voice recorder. Spexor uses a combination of noise and motion sensor signals to sense changes in the environment.

Read more
AMD previews Ryzen 7000 Zen 4 processors with Halo Infinite tease
Dr. Lisa Su presents the new AMD Zen 4 CPU.

A long-awaited announcement is finally here: AMD has just teased the upcoming release of the next generation of processors, dubbed the AMD Ryzen 7000 series.

The CPUs are set to release in the second half of 2022. AMD previewed the performance of one of the upcoming Zen 4 processors during CES 2022, showing how it fared during a Halo Infinite gaming demo.

Read more
AMD may use Samsung’s 4nm node for Chromebook processors
A digital depiction of an AMD Ryzen 5000G chip.

AMD may soon work with the Samsung chip foundry in order to prepare 4nm Chromebook processors, according to Gokul Hariharan, an analyst at J.P. Morgan.

AMD has previously only worked with two semiconductor factories -- TSMC and GlobalFoundries -- but if the report proves to be true, the cooperation with Samsung may also extend to graphics cards.

Read more