CPU security hole in AMD processors enables malware infections
Summary
At DEF CON 2024, IOActive researchers Enrique Nissim and Krzysztof Okupski presented the “Sinkclose” hole, which affects AMD processors of roughly the last ten years up to Ryzen 7000. Attackers with kernel access can use it to execute code in the privileged System Management Mode and hide from the operating system and protective software. Such an infection even survives a reinstallation and can only be prevented by a firmware update.
Ideas
- System Management Mode sits above the operating system and hypervisor.
- Malware in this mode is invisible to conventional protective software.
- The researchers informed AMD as early as October 2023.
- AMD emphasised that an attack already requires kernel access.
Insights
- High barriers to entry lose weight when hardware is already manipulated in the supply chain.
- Firmware is a patch target of its own that operating system updates do not cover.
Facts
- According to the researchers, hundreds of millions of AMD chips are affected.
- Reinstalling the operating system does not remove an SMM infection.
- The hole has the identifier CVE-2023-31315; no updates were planned for the Ryzen 3000 series.
References
Critique
- The report refers to AMD’s bulletin but itself names no firmware versions for comparison.
Recommendations
- Apply manufacturers’ BIOS and AGESA updates on older AMD systems as well.
- Treat kernel access on servers as a complete compromise that includes a firmware check.
Links to the original source and the Web Archive open in a new tab.