Skip to main content

Despite AMD CPU patch, researchers highlight more exploits could be incoming

AMD Ryzen 7 2700X sat on top the socket at a wonk.
(Image credit: Future)

Computer scientists from TU Dresden have shown it's possible to produce a Meltdown-like vulnerability in AMD's processors. In case you don't remember, AMD's chips were famously unaffected by the original Meltdown CPU exploits, while Intel's were, so this is maybe surprising news. The new exploit was demonstrated on a Ryzen 7 2700X CPU as well as with Epyc 7262 and Threadripper 2990WX silicon.

Don't worry though, AMD has developed a technique to mitigate the problem and has recommendations as to how software vendors can analyse their code for such vulnerabilities. AMD also stated how newer, and future processors support additional security features to protect against such exploits.

AMD was given time to get a solution in place, because the researchers, Saidgani Musaev and Christof Fetzer, originally shared the vulnerability with AMD back in October 2020 but have only just reported their findings. Thus giving AMD plenty of time to mitigate the problem. AMD referenced the vulnerability in a security bulletin, AMD-SB-1010.

The original research paper, "Transient Execution of Non-Canonical Accesses", showed that Zen+ and Zen 2 processors were vulnerable to specific code sequences that may lead to data leakage. It has since been shown to affect all of AMD's CPUs. This is a different method to that used by Meltdown, which relied on fetching data from the L1 data cache, but the outcome is "very similar to Meltdown-type behaviour."

Your next upgrade

(Image credit: Future)

Best CPU for gaming: the top chips from Intel and AMD
Best graphics card: your perfect pixel-pusher awaits
Best SSD for gaming: get into the game ahead of the rest

The paper does highlight that AMD's design decisions limit the exploitability of these flaws, especially when compared to Intel's CPUs, but that, "it may be possible to use them to amplify other microarchitectural attacks." So not all good news then.

Since Spectre and Meltdown appeared on the scene, both Intel and AMD have been keen to beef up the security of their processors. And it looks like such exploits aren't about to disappear any time soon. 

Alan Dexter

Alan has been writing about PC tech since before 3D graphics cards existed, and still vividly recalls having to fight with MS-DOS just to get games to load. He fondly remembers the killer combo of a Matrox Millenium and 3dfx Voodoo, and seeing Lara Croft in 3D for the first time. He's very glad hardware has advanced as much as it has though, and is particularly happy when putting the latest M.2 NVMe SSDs, AMD processors, and laptops through their paces. He has a long-lasting Magic: The Gathering obsession but limits this to MTG Arena these days.