Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

Chipmaker Patch Tuesday: Many Vulnerabilities Addressed by Intel, AMD, Nvidia

Intel, AMD and Nvidia have published security advisories describing vulnerabilities found recently in their products.

Chipmaker Patch Tuesday

Dozens of security advisories were published on Tuesday by Intel, AMD and Nvidia to inform customers about vulnerabilities found recently in their products.

Intel has published 34 new advisories this Patch Tuesday. High-severity vulnerabilities have been addressed by the company in Xeon processors, Ethernet drivers for Linux, chipset firmware, processor stream cache, 800 Series Ethernet, PROSet/Wireless, and Connectivity Performance Suite products. 

Most of them allow privilege escalation, while some can be exploited for denial of service (DoS) and information disclosure. 

Intel has addressed medium-severity issues in AI Playground, Driver & Support Assistant (DSA), Distribution for Python, PCIe Switch, AI for Enterprise Retrieval-augmented Generation, Device Plugins for Kubernetes, and TinyCBOR.

Medium-severity flaws have also been resolved in RealSense Dynamic Calibrator, Edge Orchestrator for Tiber, Clock Jitter Tool, QuickAssist Technology, UEFI, Graphics, Rapid Storage Technology, oneAPI Toolkit, Trace Analyzer and Collector, E810 Ethernet, and TDX.

Exploitation of the vulnerabilities found in these products can lead to privilege escalation, DoS, and information disclosure. 

Advertisement. Scroll to continue reading.

AMD published ten new advisories in the days leading up to and on Patch Tuesday. 

Some of the advisories published by AMD address recently published research papers. One paper comes from ETH Zurich researchers, who showed that a CPU optimization known as the stack engine can be abused for attacks that lead to information leakage. In response, AMD advised developers to follow existing best practices to mitigate the potential vulnerability.

Another paper written by ETH Zurich researchers describes Heracles, a method that enables a malicious hypervisor to execute a side-channel attack against a running SEV-SNP guest. A similar technique was reported to AMD by researchers from the University of Toronto. The company has recommended some mitigations

Several advisories describe multiple vulnerabilities found during internal and external audits in client processor platforms, server processors, embedded processors, and graphics and datacenter accelerator products.

The company also addressed a couple of physical attacks, including a Secure Boot bypass and voltage fault injection on SEV-protected virtual machines. AMD noted that physical attacks fall outside the scope of its threat model. 

AMD also informed customers about a code execution bug in EDK2 SMM, and an outdated Chromium browser version in Adrenalin driver software.

Nvidia published half a dozen advisories on Patch Tuesday. In the NeMo framework, which is designed for developing custom generative AI, the company fixed two high-severity issues that could lead to remote code execution and data tampering. 

Two high-severity flaws that can be exploited for code execution, privilege escalation, data tampering, and information disclosure have been resolved in the Megatron-LM framework for AI training. 

In the Merlin open source library for GPU-accelerated recommender systems, specifically the Transformers4Rec library, Nvidia patched a security hole that can lead to code execution, information disclosure, privilege escalation, and data tampering.

Vulnerabilities with similar potential impact have also been fixed by Nvidia in the Isaac GR00T robot development platform, and in Apex and WebDataset deep learning software — one vulnerability has been addressed in each product. 

Related: Chipmaker Patch Tuesday: Intel, AMD, Arm Respond to New CPU Attacks

Related: Chipmaker Patch Tuesday: Intel, AMD, Nvidia Fix High-Severity Vulnerabilities

Written By

Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join as speakers examine the various components of ASM strategy, the push to mandate continuous asset visibility and inventory tools, and the use of red-teaming, bug bounties and pen-tests in modern security programs.

Register

Explore what it takes to operationalize continuous authorization at scale, including the technical, organizational, and cultural changes required.

Register

People on the Move

Zero Networks has named Yossi Dagan as Chief Financial Officer.

Manifold has appointed Joe Sullivan to its Board of Directors.

Patrick McKinney has joined Turing as Chief Information Security Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.