AMD Security Vulnerabilities - June 2026

From Thomas-Krenn-Wiki
Jump to navigation Jump to search

On June 9th, 2026, AMD published the security bulletins AMD-SB-3039[1] and AMD-SB-9025[2] for security vulnerabilities.

Information

AMD-SB-3039: This is a malicious hypervisor that can undermine the integrity protection mechanisms of AMD Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP), by forcing AMD Security Processor (ASP) to work with the system storage without cache coherence. According to the publication, system settings controlled by the hypervisor enable the reconfiguration of the interaction between the storage requirements of the ASP and the CPU-cache. By disabling coherence, the ASP can read stale data from the DRAM when copying pages and updating the associated metadata, causing the guest to lose the most recent updates in the CPU cache. This could potentially undermine the integrity warranties of the SEV-SNP for guests and could cause data corruption.

AMD-SB-9025: The vulnerability could allow a local attacker with user privileges to write to memory assigned by the kernel. AMD confirms that the issue occurs because from the driver creating a shared-section object with a NULL security descriptor and exposing kernel pointers in shared memory, which could allow an attacker to write to kernel-allocated memory and potentially cause a system crash or a denial-of-service condition.

Affected systems

Here is a table listing the affected processors.

AMD EPYC™ Processors
Product Mitigation
AMD EPYC™ 8004 Series Processors GenoaPI

1.0.0.H

AMD EPYC™ 9004 Series Processors GenoaPI

1.0.0.H

AMD EPYC™ 9005 Series Processors TurinPI

1.0.0.8

AMD EPYC™ Embedded 8004 Series Processors EmbGenoaPI-SP5

1.0.0.D

AMD EPYC™ Embedded 9004 Series Processors

(formerly codenamed "Genoa")

EmbGenoaPI-SP5

1.0.0.D

AMD EPYC™ Embedded 9004 Series Processors

(formerly codenamed "Bergamo")

EmbGenoaPI-SP5

1.0.0.D

AMD EPYC™ Embedded 9005 Series Processors EmbeddedTurinPI_SP5

1004


CVE CVSS Score
CVE-2025-54509 4.0 (Medium)
CVE-2026-0466 6.8 (Medium)
CVE-2026-28237 6.8 (Medium)

In the following, there is an extract of this table in which all Supermicro mainboards are included that are offered by Thomas-Krenn:[3]

AMD motherboard BIOS version
H13SSW 3.8
H13SSL-N/NT 3.8

Updates for Thomas-Krenn products

Updates on the corresponding system can be found in the download area of Thomas-Krenn. The updates in the download area have been tested by us to guarantee the stability and compatibility of our systems.

If you require the latest version for your system and it is not yet available in our download area, you can get it at Asus, Supermicro or Gigabyte

References

  1. ASP non-Coherent Memory Access – June 2026 (www.amd.com/en/resources/product-security)
  2. AMD uProf Vulnerabilities – June 2026 (www.amd.com/en/resources/product-security)
  3. AMD Security Bulletin AMD-SB-3027, January 2027 (www.supermicro.com)

More information


Author: Thomas-Krenn.AG

At Thomas-Krenn.AG we pay attention to the best possible service. To do justice to this, we have created our Thomas-Krenn Wiki. Here we share our knowledge with you and inform you about basics and news from the IT world. You like our knowledge culture and want to become part of the team? Visit our job offers.

 

Translator: Alina Ranzinger

Alina has been working at Thomas-Krenn.AG since 2024. After her training as multilingual business assistant, she got her job as assistant of the Product Management and is responsible for the translation of texts and for the organisation of the department.


Related articles

AMD Security Vulnerabilities - April 2026
Safety instructions for AMD-SB-3027
Safety Instructions for AMD-SB-7027 AMD SMM vulnerabilities