Skip to main content

Millions of AMD chips are being ignored in major security flaw fix

CPU pads on the AMD Ryzen 7 9700X.
Jacob Roach / Digital Trends

Hundreds of millions of AMD CPUs are facing a new vulnerability called Sinkhole. The exploit, which was first reported by Wired, impacts processors dating back to 2006, and it spans nearly all of AMD’s products. That list includes Ryzen, Threadripper, and Epyc CPUs across desktop and mobile, as well as AMD’s data center GPUs. Despite Sinkhole hitting some of AMD’s best processors, only the most recent batch of chips will receive a patch that fixes the vulnerability.

AMD isn’t patching Ryzen 1000, 2000, or 3000 processors, nor is it patching Threadripper 1000 and 2000 CPUs, reports Tom’s Hardware. The company claims that these older CPUs fall outside of its support window, despite the fact that millions are still in use. Still, even the most recent Ryzen 3000 chips were released over five years ago, and it makes sense that AMD would want to focus its support on new chips like the Ryzen 5 9600X and Ryzen 7 9700X.

Recommended Videos

Make no mistake, Sinkhole is a major security flaw. However, it’s not an exploit the vast majority of users need to worry about. Sinkhole, which was discovered by researchers at IOActive, allows attackers to run code in System Management Mode. This operating mode allows close access to the hardware, and it’s where you’ll find firmware running for power management settings, for example. Wired reports that the malware can dig down so deep that it’s easier to discard an infected computer rather than repair it.

Get your weekly teardown of the tech behind PC gaming
Check your inbox!

Sounds scary, but an attacker would already need to have deeply infected your PC in order for Sinkhole to play a role. The researchers pointed to something like a bootkit as an example, which runs malicious code before the operating system loads in order to evade antivirus software. AMD says that attackers would already need access to the OS kernel in order for Sinkhole to be on the table. In other words, it would need to be a highly targeted attack on a severely compromised PC. It’s an exploit that should almost never occur on a consumer PC.

Anyone targeted by Sinkhole should get ready for trouble. The researchers say the exploit is so deep that it wouldn’t be picked up antivirus software, regardless of how sophisticated it is, and that malicious code can persist even through a reinstall of the operating system.

AMD has or is going to release a patch for its most recent chips. For consumers, that includes mobile processors dating back to AMD Athlon 3000, and for desktop, we’re talking processors dating back to Ryzen 5000. Although you shouldn’t worry much that Sinkhole will be exploited on your PC, it’s a good idea to patch your processor regardless. AMD says the update won’t come with a performance loss, and a little extra security never hurt anyone.

Jacob Roach
Lead Reporter, PC Hardware
Jacob Roach is the lead reporter for PC hardware at Digital Trends. In addition to covering the latest PC components, from…
4 CPUs you should buy instead of the Ryzen 7 9800X3D
The Ryzen 7 9800X3D held between fingertips.

I'm not going to even pretend the Ryzen 7 9800X3D is a bad CPU. It's one of the best processors you can buy, and undoubtedly the best processor you can buy for gaming. There are just a couple of problems. It's pretty expensive at nearly $500 for an eight-core CPU. Also, at the time of writing, it's sold out everywhere -- and signs don't point to it being back in stock any time soon.

You don't need to wait. The Ryzen 7 9800X3D, for as impressive as it is, isn't the right processor for everyone. In fact, I'm using an entirely different processor in my personal high-end gaming PC, and for a lot of gamers, the extra price you pay for the AMD's 3D V-Cache could go to waste. Here are four CPUs that you can not only pick up now, but they also provide solid competition for the Ryzen 7 9800X3D, be it on price, performance, or both.
Ryzen 7 7800X3D

Read more
Everyone hates this AMD CPU, but I still use it in my PC
A small form factor build inside the Fractal Terra.

Gamers Nexus called it a "wasted opportunity." Hardware Unboxed declared it a "flop." Even in our own Ryzen 7 9700X review, I said the CPU doesn't have "enough meat on the bone to justify an upgrade." So, why does the Ryzen 7 9700X top the list of the best processors? And more importantly, why am I using one in my personal PC?

I'll do my best to answer these forced questions. The disappointment in the Ryzen 7 9700X isn't truly universal -- no opinions about PC hardware are -- but there's no doubt that it's the outcast in AMD's lineup of Ryzen 9000 CPUs. It's not great for gaming in the face of the Ryzen 7 9800X3D, and you can save $50 to $70 with the Ryzen 7 7700X while getting largely similar productivity performance. But AMD's trusty little Zen 5 octa-core is still at the heart of my high-end gaming PC, and I wouldn't have it any other way.
A flexible little devil

Read more
Intel admits defeat on Arrow Lake — but it’s not down for the count
intel core ultra 5 245k review 4

Intel's Arrow Lake CPUs aren't off to a great start. As you can read in our Core Ultra 9 285K review and Core Ultra 5 245K review, Intel's latest CPUs miss the mark across productivity and gaming apps, and they're miles away from some of the best processors you can buy right now. According to Intel, there are several issues with the new platform that it plans to address within a matter of weeks.

In an interview with HotHardware, Intel's Robert Hallock was blunt about the release of Arrow Lake CPUs: "The launch didn't go as planned ... we have a number of things we got to go fix." Hallock, formerly of AMD, is near the top of Intel's technical marketing division. Although he didn't address exactly what's wrong with Arrow Lake, Hallock promised that Intel is working on updates that could significantly improve performance, and that they'll arrive in a matter of weeks.

Read more