News

AMD warns worrying new Spectre, Meltdown-esque flaw could affect top CPUs - here's what we know - Thursday, July 10, 2025 - 09:03
  • AMD finds four flaws, separately low in severity, but powerful when combined
  • Together, they can be abused in information disclosure attacks
  • The list of affected devices is rather extensive, so be on your guard

AMD has discovered several security vulnerabilities affecting many of its chips can be chained together to create a concerning hack which could result in information disclosure.

The four vulnerabilities are tracked as CVE-2024-36349 (3.8), CVE-2024-36348 (3.8), CVE-2024-36357 (5.6), and CVE-2024-36350 (5.6). Together, they can be used in a so-called Transient Scheduler Attack (TSA), a side-channel, or timing-based attack that likely exploits transient scheduling decisions made by the CPU scheduler to leak information.

Since this is a side-channel attack that results in information disclosure, it is similar to the infamous Meltdown and Spectre flaws which dominated the security scene for months.

Updating the systems

Separately, the vulnerabilities were given relatively low severity scores, since the devices need to be compromised in advance, either by physical presence, or through malware, before they can be leveraged.

Furthermore, the TSA would need to be executed many times before any meaningful data could be extracted.

Here is how a theoretical attack would occur: A CPU expects load instructions to complete rather quickly. However, if there is a condition that prevents them from doing so, a “false completion” happens. Since the load didn’t complete, the data from the load is forwarded to dependent operations, affecting the timing of the instructions the CPU executes - something the attackers can observe.

The worst-case scenario is AMD chips leaking OS kernel information - but other applications or VMs could leak data as well.

A patch is already available, and AMD advised system admins to update to the latest Windows versions as soon as possible.

Those who are unable to install the patch quickly can implement a workaround involving a VERW instruction, but AMD has advised against it since it could reduce the performance of the system. In any case, the details about the mitigation can be found here.

The full list of all affected chips, including EPYC, Ryzen, Instinct, Ahtlon, and others, can be found in AMD’s advisory.

Via The Register

You might also like
Best VPN for Amazon Fire TV Stick in 2025 - Thursday, July 10, 2025 - 08:00
A VPN lets you stream foreign content at home or access geo-restricted videos from home while traveling. Here are the best VPNs for Amazon Fire TV devices to augment your streaming journey.
You May See Less AI Slop After YouTube Enacts New Video Policies - Thursday, July 10, 2025 - 11:45
The company says it's making a minor change in how it pays video creators, but it could have big implications for viewers.
Mycopunk Review: It's Deep Rock Galactic With a Fungal Infection - Thursday, July 10, 2025 - 12:00
This new co-op shooter combines fluid movement, hero skills and crunchy-feeling gunplay to great effect.
We Tested EveryPlate, the Meal Kit Service That's Cheaper Than Buying Groceries - Thursday, July 10, 2025 - 12:00
EveryPlate has the cheapest meal kits but are they any good? Three CNET editors tried the budget-friendly service to see how it compared with more expensive options.
Outlook Down: Microsoft Confirms Email Outage, Working on Fix - Thursday, July 10, 2025 - 12:15
Some Outlook users are currently unable to access their email, either through web browser, mobile app or desktop client.
Make Sure Your Phone Will Give You Loud and Clear Emergency Alerts - Thursday, July 10, 2025 - 13:46
How to enable severe weather alerts on iPhone, Android and more.
Best Internet Providers in Michigan - Thursday, July 10, 2025 - 14:03
Throughout the state of Michigan there are high speeds and good prices if you know where to look.
Student Loan Update: Here's What SAVE Borrowers Should Do by August 1 - Thursday, July 10, 2025 - 14:21
Borrowers enrolled in the Saving on a Valuable Education plan just had another curveball thrown at them.
Prime Day Deal: This Multidevice Keyboard Is the Key to Decluttering My Workspace, and It's Currently 15% Off - Thursday, July 10, 2025 - 14:32
I have way too many computers, and the Logitech K780 is one way I can avoid having too many keyboards. It's a great option that's $60 for Prime Day.
Prime Day Deal: I've Finally Found an Unscratchable Electric Griddle, and It's 30% Off Now - Thursday, July 10, 2025 - 14:58
This ceramic griddle can actually stand up to my favorite metal utensils. Right now, it's less than $50 on Amazon.
Measles Cases Hit the Highest Number in 33 Years. Do You Need a Measles Vaccine Booster? - Thursday, July 10, 2025 - 15:25
The number of measles cases in the US has risen to a record level. Learn how to protect yourself.
Best iPad of 2025: Top iPad Air, iPad Mini, iPad Pro Picks - Thursday, July 10, 2025 - 15:25
CNET experts list the best iPads that suit your needs.
Prime Day Deal: This Tiny 5-In-1 Fan Is Part of My Summer Survival Kit and It's 26% Off Right Now - Thursday, July 10, 2025 - 15:49
You won't catch me outside without the JisuLife Ultra2 -- the incredibly powerful, yet pocket-sized fan that also works as a battery pack, flashlight and more.
Today's Wordle Hints, Answer and Help for July 11, #1483 - Thursday, July 10, 2025 - 16:00
Here are hints and the answer for today's Wordle for July 11, No. 1,483.
Today's NYT Connections Hints, Answers and Help for July 11, #761 - Thursday, July 10, 2025 - 16:00
Here are some hints and the answers for the NYT Connections puzzle for July 11, #761.
Today's NYT Strands Hints, Answers and Help for July 11 #495 - Thursday, July 10, 2025 - 16:00
Here are hints and answers for the NYT Strands puzzle for July 11, No. 495.
Best Laptops We've Tested (July 2025) - Thursday, July 10, 2025 - 16:20
These are the best laptops that my colleagues and I have reviewed in the past year, spanning all types, sizes and prices.
Best Carpet Cleaners: I Used Real Life Messes as the Ultimate Test - Thursday, July 10, 2025 - 17:45
What do chocolate syrup, ketchup, red wine and pet urine have in common? These were poured all over a white carpet during CNET's carpet cleaner testing.
Netflix Jumped In on the Shark Week Action in July, Landing Two New Hits - Thursday, July 10, 2025 - 18:00
Commentary: Two new shark-related programs are among Netflix's most popular this week, but it's a big month for sharks on streaming services.

Pages