AMD Security Vulnerabilities - June 2026
On June 9th, 2026, AMD published the security bulletins AMD-SB-3039[1] and AMD-SB-9025[2] for security vulnerabilities.
Information
AMD-SB-3039: This is a malicious hypervisor that can undermine the integrity protection mechanisms of AMD Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP), by forcing AMD Security Processor (ASP) to work with the system storage without cache coherence. According to the publication, system settings controlled by the hypervisor enable the reconfiguration of the interaction between the storage requirements of the ASP and the CPU-cache. By disabling coherence, the ASP can read stale data from the DRAM when copying pages and updating the associated metadata, causing the guest to lose the most recent updates in the CPU cache. This could potentially undermine the integrity warranties of the SEV-SNP for guests and could cause data corruption.
AMD-SB-9025: The vulnerability could allow a local attacker with user privileges to write to memory assigned by the kernel. AMD confirms that the issue occurs because from the driver creating a shared-section object with a NULL security descriptor and exposing kernel pointers in shared memory, which could allow an attacker to write to kernel-allocated memory and potentially cause a system crash or a denial-of-service condition.
Affected systems
Here is a table listing the affected processors.
AMD EPYC™ Processors
| Product | Mitigation |
| AMD EPYC™ 8004 Series Processors | GenoaPI
1.0.0.H |
| AMD EPYC™ 9004 Series Processors | GenoaPI
1.0.0.H |
| AMD EPYC™ 9005 Series Processors | TurinPI
1.0.0.8 |
| AMD EPYC™ Embedded 8004 Series Processors | EmbGenoaPI-SP5
1.0.0.D |
| AMD EPYC™ Embedded 9004 Series Processors
(formerly codenamed "Genoa") |
EmbGenoaPI-SP5
1.0.0.D |
| AMD EPYC™ Embedded 9004 Series Processors
(formerly codenamed "Bergamo") |
EmbGenoaPI-SP5
1.0.0.D |
| AMD EPYC™ Embedded 9005 Series Processors | EmbeddedTurinPI_SP5
1004 |
| CVE | CVSS Score |
| CVE-2025-54509 | 4.0 (Medium) |
| CVE-2026-0466 | 6.8 (Medium) |
| CVE-2026-28237 | 6.8 (Medium) |
In the following, there is an extract of this table in which all Supermicro mainboards are included that are offered by Thomas-Krenn:[3]
| AMD motherboard | BIOS version |
|---|---|
| H13SSW | 3.8 |
| H13SSL-N/NT | 3.8 |
Updates for Thomas-Krenn products
Updates on the corresponding system can be found in the download area of Thomas-Krenn. The updates in the download area have been tested by us to guarantee the stability and compatibility of our systems.
If you require the latest version for your system and it is not yet available in our download area, you can get it at Asus, Supermicro or Gigabyte
References
- ↑ ASP non-Coherent Memory Access – June 2026 (www.amd.com/en/resources/product-security)
- ↑ AMD uProf Vulnerabilities – June 2026 (www.amd.com/en/resources/product-security)
- ↑ AMD Security Bulletin AMD-SB-3027, January 2027 (www.supermicro.com)
More information
- AMD Security Bulletin AMD-SB-3039 (supermicro.com, Juni 2026)
|
Author: Thomas-Krenn.AG At Thomas-Krenn.AG we pay attention to the best possible service. To do justice to this, we have created our Thomas-Krenn Wiki. Here we share our knowledge with you and inform you about basics and news from the IT world. You like our knowledge culture and want to become part of the team? Visit our job offers. |
|
Translator: Alina Ranzinger Alina has been working at Thomas-Krenn.AG since 2024. After her training as multilingual business assistant, she got her job as assistant of the Product Management and is responsible for the translation of texts and for the organisation of the department.
|


