AMD Product Security Update Advisory (CVE-2024-56161)

Overview

We have released a security update to fix vulnerabilities in AMD products. Users of affected products are advised to update to the latest version.
 

 

 

Affected Products

 

CVE-2024-56161

AMD EPYC™ 7001 Series Versions: ~NaplesPI 1.0.0.P (excluding)
AMD EPYC™ 7002 Series Versions: ~RomePI 1.0.0.L (excluding)
AMD EPYC™ 7003 Series versions: ~MilanPI 1.0.0.F (excluding)
AMD EPYC™ 9004 Series versions: ~Genoa 1.0.0.E (excluding)

 

 

Resolved Vulnerabilities

Improper signature verification vulnerability that could allow an attacker with local administrator privileges to load malicious CPU microcode (CVE-2024-56161)

 

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest updates. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2024-56161

AMD EPYC™ 7001 Series versions: NaplesPI 1.0.0.P
AMD EPYC™ 7002 Series Version: RomePI 1.0.0.L
AMD EPYC™ 7003 Series version: MilanPI 1.0.0.F
AMD EPYC™ 9004 Series version: Genoa 1.0.0.E

 

 

 

References

[1] AMD SEV Confidential Computing Vulnerability
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-3019.html