Breaking
SecurityDeveloping Story

Chipmakers Patch Over 80 Bugs, Including Severe Flaws

Intel and AMD release combined patches for more than 80 vulnerabilities, including high-severity issues in processors and software.

··2 hours ago·2 min read
a close up of a motherboard with a cpu chip
Photo by Rémy on Unsplash

Chipmakers Intel and AMD each released security advisories on Tuesday, together addressing more than 80 vulnerabilities across a wide range of products, from server processors to development tools and wireless software.

Intel published 42 advisories covering 72 vulnerabilities, while AMD issued five advisories detailing a dozen flaws. The patches come as part of the companies' regular Patch Tuesday updates.

High-Severity Flaws in Intel Products

According to Intel, several high-severity vulnerabilities were patched in its PROSet/Wireless WiFi software, which could allow an attacker to escalate privileges or conduct a denial-of-service (DoS) attack.

Other high-severity issues were addressed in Xeon processors, Data Center Attestation Primitives, Alias Checking Trusted Module for Xeon processors, TDX, Active Management Technology, PROSet/Wireless WiFi software, and CSME and SPS. These flaws could lead to privilege escalation, local code execution, or denial-of-service.

Intel's Medium-Severity Fixes

Intel also patched medium-severity vulnerabilities in a variety of software products, including Transfer Learning Tool, Extension for PyTorch, LLM-on-Ray, Gaudi Container Runtime, Performance Counter Monitor, vLLM Hardware Plugin for Gaudi, Approximate Bayesian Inference Framework, Hardware Aware Automated Machine Learning, EquiTriton Software, and Workload Services Framework.

Additional medium-severity issues were resolved in LLM Scaler, LLM Library and oneCCL Bindings for PyTorch, TDX DCAP and Guest, AI Containers, Cluster Management Toolkit for Kubernetes, Open VKL, Extension for TensorFlow, NPU Drivers, Neural Compressor, Battery Life Diagnostic Tool, Xeon and Core Ultra, UEFI Reference BIOS, AI Reference Models, CSME, and SPS products. These vulnerabilities could be exploited for privilege escalation, denial-of-service, or information disclosure.

The company also fixed a low-severity vulnerability in Slim Bootloader.

AMD's Advisories Cover a Dozen Bugs

AMD's advisories describe five high-severity issues in the Vitis development environment. Exploitation of these flaws could lead to private key disclosure, privilege escalation, and arbitrary code execution.

The chipmaker also addressed arbitrary code execution issues in Ryzen Master Utility, SEV-SNP, and Power Design Manager.

Earlier This Month

Earlier this month, AMD informed customers about a Safe RET interrupt vulnerability and a recently disclosed SEV attack method dubbed PowerHooK. These are separate from the new advisories.

  • Intel: 42 advisories, 72 vulnerabilities
  • AMD: 5 advisories, 12 vulnerabilities
  • Combined: more than 80 vulnerabilities

What This Means for Businesses

For IT teams and security professionals, the breadth of these patches underscores the importance of staying current with firmware and software updates from both chipmakers. While none of these flaws are confirmed to have been exploited in the wild, the potential impact of high-severity issues in foundational components like processors and security modules makes timely patching critical.

As chipmakers increasingly bundle hardware and software, the responsibility to keep pace with patches falls on both the vendors and the users of their products. Organizations should review the advisories and assess their exposure to these vulnerabilities.

#intel#amd#patch tuesday#vulnerabilities#security

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted through our automated editorial pipeline from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our Automation Policy →

← Back to all stories