Patch Tuesday: Intel, AMD patch 80+ security flaws
Intel and AMD released Tuesday updates that fix more than 80 vulnerabilities across firmware, processors, management tools and AI components.
On Tuesday, Intel and AMD released security updates addressing more than 80 vulnerabilities across their product lines. Intel published 42 advisories covering 72 distinct flaws, and AMD issued five advisories covering about a dozen vulnerabilities.
Intel’s advisories include several high-severity fixes in networking and platform firmware. Patches for PROSet/Wireless Wi-Fi software cover flaws that could allow local code execution, privilege escalation or denial-of-service. High-severity issues were fixed in Xeon processors that could permit privilege escalation, in Data Center Attestation Primitives that might disclose information, in an Alias Checking Trusted Module for Xeon with privilege escalation risk, and in TDX and Active Management Technology with privilege escalation and DoS impacts, respectively. Intel released CSME and SPS firmware updates that address additional privilege-escalation weaknesses and closed a low-severity issue in the Slim Bootloader.
Intel issued medium-severity fixes across multiple AI development and deployment tools. Affected products named in the advisories include the Transfer Learning Tool, Extension for PyTorch, LLM-on-Ray, Gaudi Container Runtime, Performance Counter Monitor, the vLLM hardware plugin for Gaudi, LLM Scaler, LLM Library, oneCCL bindings for PyTorch, TDX DCAP and Guest components, AI Containers, the Cluster Management Toolkit for Kubernetes, Open VKL, Extension for TensorFlow, NPU drivers, Neural Compressor, Battery Life Diagnostic Tool, Xeon and Core Ultra platforms, the UEFI Reference BIOS and several AI reference models. Intel’s advisories state these issues can enable privilege escalation, information disclosure or service disruption.
AMD’s advisories cover about a dozen vulnerabilities, including five high-severity issues in the Vitis development environment that could expose private keys, allow privilege escalation or permit arbitrary code execution. AMD patched arbitrary code execution flaws in Ryzen Master Utility, SEV-SNP components and the Power Design Manager tool. Earlier in the month the company disclosed a Safe RET interrupt vulnerability and a new SEV attack technique called PowerHooK; the recent advisories provide additional mitigation and remediation guidance.
Both companies published technical notes and recommended remediation steps in their advisories. Administrators and users are advised to review the vendor advisories and apply firmware and software updates as directed. Systems that host sensitive keys, production servers or development environments that run untrusted code should be prioritized for updates.








