THE TAKEAWAY: AMD has published a new security bulletin about the Trusted Platform Module reference implementation used in its computer platforms. The disclosed flaws could have significant reliability and security implications, but updates for AMD's numerous CPU families have already been available for months. Users simply need to install them.

Researchers working with the Trusted Computing Group recently identified a potential security issue in AMD's TPM code, prompting the company to release new motherboard and firmware updates to address the vulnerability. The update process was not exactly swift, however, as the fixed TPM code had already been available for months. Meanwhile, AMD has only just released its AMD-SB-7064 bulletin detailing the issue.

The US chipmaker explained that the TCG Vulnerability Response Team was informed by Intel researchers about a potential out-of-bounds read vulnerability in its TPM 2.0 reference code. The flaw could be exploited by local attackers with elevated user privileges, allowing them to force the TPM code to read sensitive data stored in the firmware or even affect the availability of the TPM.

AMD programmers confirmed the issue, which affects the company's TPM implementation in two different ways. The first flaw (CVE-2026-6726) could leak information and allow a malicious actor to recover credentials from a TPM-aware Certificate Authority, potentially enabling them to falsify TPM encryption keys or other TPM-based attestation mechanisms.