logo

Google: How to make any AMD Zen CPU always generate 4 as a random number

ID: a0573f63-3f59-5898-8cbb-3bf846201c17

STIX ID: report--a0573f63-3f59-5898-8cbb-3bf846201c17

Feed Name: The Register (Security)

Threat Score
75/100

Date Published: 2025-02-04

Date Updated: 2026-04-26

Author: Iain Thomson

...
...

**Executive summary:** Google Security researchers demonstrated a weakness in AMD microcode signature validation (CVE-2024-56161) allowing crafted microcode updates to be accepted by Zen1–Zen4 processors; their proof-of-concept forces the RDRAND instruction to return a constant (4). The issue can undermine AMD SEV/SEV-SNP confidential computing guarantees and dynamic root-of-trust, but exploitation requires host kernel (ring-0) privileges; AMD has issued microcode mitigations and firmware/BIOS patches to address the flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.