Skip to main content

You are not logged in. Your edit will be placed in a queue until it is peer reviewed.

We welcome edits that make the post easier to understand and more valuable for readers. Because community members review edits, please try to make the post substantially better than how you found it, for example, by fixing grammar or adding additional resources and hyperlinks.

Required fields*

6
  • 2
    The signing key for AMD Zen 1-4 cpus has leaked , meaning AMD CPUs between at least 2017-2022 are vulnerable to malicious microcode updates. Commented Oct 13 at 10:45
  • 2
    actually seems Zen 5 is also affected, cpus up to 2025-03-04 seems to be affected: github.com/google/security-research/security/advisories/… - conflicting reports, some places say Zen 1-4, but the github advisory page also mention Zen 5 and "PI < 2025-03-04" 🤔 Commented Oct 13 at 10:53
  • Ah, good to know, thanks @hanshenrik! Commented Oct 13 at 10:57
  • 2
    It's not that the signing key has been leaked; rather, there's a flaw in the signature verification procedure that lets an attacker create additional keypairs that will be accepted as valid. Commented Oct 14 at 1:13
  • 1
    @Mark Both, it seems. quote We were then able to recover the Zen 5 key on March 7, 2025 and reported this to AMD. We then jointly added Zen 5 to the list of affected products to our advisories on April 7, 2025. Commented Oct 14 at 8:58