# ‘Sinkclose’ Flaw in Hundreds of Millions of AMD Chips Allows Deep, Virtually Unfixable Infections

**URL:** https://discuss.privacyguides.net/t/sinkclose-flaw-in-hundreds-of-millions-of-amd-chips-allows-deep-virtually-unfixable-infections/19979
**Category:** General
**Tags:** article
**Created:** 2024-08-10T14:50:27Z
**Posts:** 6

## Post 1 by @dngray — 2024-08-10T14:50:27Z

> **[‘Sinkclose’ Flaw in Hundreds of Millions of AMD Chips Allows Deep, Virtually...](https://www.wired.com/story/amd-chip-sinkclose-flaw/)**
>
> Researchers warn that a bug in AMD’s chips would allow attackers to root into some of the most privileged portions of a computer—and that it has persisted in the company’s processors for decades.

---

## Post 2 by @Breeze7846 — 2024-08-10T15:33:26Z

Ah great. Another deep hack to create a bootkit.

While I do want to stress this requires serious prior infection… Its still a bad infection.

So what are Linux users supposed to do? Even windows AV will struggle to detect this stuff. What can an average user, windows or Linux, do to prevent this exploit or make sure they are safe? Or is every privacy person now expected to purge their AMD computers and buy a new one?

---

## Post 3 by @dngray — 2024-08-12T05:04:54Z

> [@Breeze7846](#):
>
> every privacy person now expected to purge their AMD computers and buy a new one?

No, just make sure you apply OS patches and don’t worry too much about it as there isn’t really anything more you can do. The only thing it does highlight is both Intel and AMD are going to be and are focusing on things which allow for persistent malware.

---

## Post 4 by @whoami5 — 2024-08-14T07:03:02Z

Isn’t this vuln patched with a bios update ?  
[https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html](https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7014.html)

Also, 3000 series Ryzen or older are affected but have a “no fix planned” which is really scummy.

---

## Post 5 by @anon63378630 — 2024-08-23T12:19:01Z

afaict today’s [real-ucode](https://github.com/divestedcg/real-ucode) update includes these fixes for the following cpuids:

- 00860F01
- 00870F10
- 00A00F10
- 00A00F11
- 00A00F12
- 00A10F11
- 00A10F12
- 00A10F81
- 00A20F12
- 00A50F00
- 00A60F12
- 00A70F52
- 00A70F80
- 00AA0F02
- 00B20F40
- 00B40F00
- 00B40F40

It appears that these fixed microcodes were made back in February and largely released for Epyc in May, but the consumer Ryzen microcodes have been added over the past week thanks to user @westlake from the winraid forum.

This is again useful because none of my boards have had EFI updates for this issue yet for example.

---

## Post 6 by @whoami5 — 2024-09-08T19:10:35Z

> **[AMD's Ryzen 3000 CPUs to get SinkClose patch after all](https://www.theregister.com/2024/08/20/amd_sinkclose_ryzen_3000/)**
>
> Still no love for 1000- or 2000-series

AMD CPUs dating as far back as 2006 are affected. Inititally, Ryzen 3000 series was given the status of “no fix planned”. They have reconsidered that decision and it got patched after all.

Seems like AMD dropped security support for zen and zen+, even though all ryzen desktop processors are listed as “in scope” in their [security support policy.](https://www.amd.com/en/resources/product-security/support-policy.html)

> The AMD products listed below are considered in-scope for Security Support:  
> Hardware products:  
> [..]  
> AMD Ryzen™ processors
