Google: How to make any AMD Zen CPU always generate 4 as a random number
ID: a0573f63-3f59-5898-8cbb-3bf846201c17
STIX ID: report--a0573f63-3f59-5898-8cbb-3bf846201c17
Feed Name: The Register (Security)
**Executive summary:** Google Security researchers demonstrated a weakness in AMD microcode signature validation (CVE-2024-56161) allowing crafted microcode updates to be accepted by Zen1–Zen4 processors; their proof-of-concept forces the RDRAND instruction to return a constant (4). The issue can undermine AMD SEV/SEV-SNP confidential computing guarantees and dynamic root-of-trust, but exploitation requires host kernel (ring-0) privileges; AMD has issued microcode mitigations and firmware/BIOS patches to address the flaw.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
