AMD reveals TPM security flaws

AMD has disclosed two high-severity vulnerabilities affecting TPM 2.0 implementations used across a wide range of Ryzen processors. The new AMD-SB-7064 bulletin was published yesterday, but the required firmware fixes had already been supplied to motherboard and system makers several weeks earlier.
The vulnerabilities are tracked as CVE-2026-6726 and CVE-2026-6727, with CVSS 4.0 scores of 8.5 and 8.3 respectively. AMD says its Firmware TPM implementations are affected. The first flaw can allow a local attacker with elevated privileges to obtain credentials for a falsified TPM key and falsify TPM attestations. The second is an RSA OAEP timing side-channel that can expose encrypted TPM data or allow falsified Attestation Keys. Both issues were reported to the Trusted Computing Group by Intel security researchers.
Affected Ryzen series include Ryzen 3000 through Ryzen 9000, Ryzen AI 300/400, Ryzen AI Max 300, Threadripper, Ryzen Z1/Z2 and several Ryzen Embedded families.
AMD supplied the fixes in May
AMD’s mitigation table shows that most desktop fixes were actually completed in May. Ryzen 3000 received ComboAM4PI 1.0.0.11 on May 18, while Ryzen 4000 and Ryzen 5000 use ComboAM4v2PI 1.2.0.12 released to OEMs on May 27. For Ryzen 7000, Ryzen 8000 and Ryzen 9000 systems, AMD lists mitigated ComboAM5PI revisions including 1.3.0.1b from May 21 and 1.2.0.3k from May 31. Those AGESA versions have already appeared in retail motherboard BIOS updates.
© AMD AM5 boards were updated before the disclosure
The same applies to AM5. ASUS had ComboAM5 PI 1.3.0.1b on boards such as the PRIME X870-P WIFI in June, followed by 1.3.0.1b Patch A on July 2. MSI released 1.3.0.1b Patch A for several B650 and X670E boards in early July. ASRock rolled out 1.3.0.1b Patch A across B650, B850 and A620 models during the second half of July. GIGABYTE shipped 1.3.0.1b Patch A in June.
Source: AMD