AMD’s TPM implementation includes two high-severity flaws, but fixes have been available since May

The Importance of Updating AMD’s TPM Code

AMD recently released a security bulletin regarding vulnerabilities in the Trusted Platform Module (TPM) reference implementation used in its computer platforms. The disclosed flaws could have serious reliability and security implications, but updates for AMD’s various CPU families have been available for months. Users are advised to install these updates promptly.

Researchers collaborating with the Trusted Computing Group discovered a potential security issue in AMD’s TPM code, leading to the release of new motherboard and firmware updates to address the vulnerability. Although the update process was not immediate, the fixed TPM code has been available for months. AMD has now released the AMD-SB-7064 bulletin outlining the issue.

AMD was informed by Intel researchers about a potential out-of-bounds read vulnerability in its TPM 2.0 reference code. This flaw could be exploited by local attackers with elevated user privileges, enabling them to access sensitive data stored in the firmware or impact the TPM’s availability.

The identified flaws in AMD’s TPM implementation have significant implications. The first flaw (CVE-2026-6726) could lead to information leakage, allowing malicious actors to retrieve credentials from a TPM-aware Certificate Authority and potentially falsify TPM encryption keys.

The second flaw (CVE-2026-6727) is a timing side-channel vulnerability affecting decryption workloads using the RSA cryptosystem. This flaw could enable attackers to decrypt encrypted data or falsify TPM 2.0 attestation keys. While both vulnerabilities require local privileged user access, they should not pose a significant risk to systems solely exposed to the internet.

Despite the threat level, these flaws have been assigned high CVSS scores of 8.5 and 8.3, respectively, and impact a wide range of processors, including Epyc 4004 and 4005 Series CPUs, Ryzen desktop CPUs from the 3000 to 9000 series, Threadripper workstation processors, and more.

AMD recommends users to install the updated Platform Initialization firmware releases addressing both CVE-2026-6726 and CVE-2026-6727. The fixed firmware versions have been available since at least May for most processors, with Ryzen Embedded CPUs receiving their updated firmware in July.

The Trusted Platform Module, established by the TCG in 2003, saw a major upgrade to TPM 2.0 in 2014. TPM 2.0 hardware or firmware implementation is now a mandatory requirement for Windows 11, enhancing security in the Windows ecosystem.

Despite advancements in TPM technology, these AMD flaws highlight that achieving total security in the modern TPM-enabled PC environment remains a work in progress.

Leave a Reply

Your email address will not be published. Required fields are marked *