AMD won’t patch Sinkclose security bug on older Zen CPUs
ID: 33c183a3-8420-57d3-8e1a-9bae7bfea78e
STIX ID: report--33c183a3-8420-57d3-8e1a-9bae7bfea78e
Feed Name: The Register (Security)
The report covers SinkClose (CVE-2023-31315), an AMD SMM privilege-escalation vulnerability (CVSS 7.5) disclosed by IOActive that lets attackers with kernel privileges run code in System Management Mode, enabling stealthy, persistent control at BIOS/firmware level. AMD has issued advisories and provided firmware or microcode mitigations for many recent Epyc and Ryzen models but initially excluded some older/unsupported desktop CPUs, reducing but not eliminating the overall risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
