Skip to main content
AMD Security Bulletin AMD-SB-7064, August 2026

Supermicro is aware of the potential vulnerabilities in AMD EPYC™, AMD Athlon™, and AMD Ryzen™, with the Trusted Platform Module (TPM) reference code errata. One issue may result in information leakage. The second issue may allow elevated privileges to obtain a credential from a TPM-aware Certificate Authority (CA), potentially leading to a falsified TPM key. This vulnerability affects BIOS in the Supermicro client motherboard products.

CVE IDSeverityDescription
CVE-2026-67268.5 High
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
An information-leakage issue vulnerability was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to obtain a credential from a TPM-aware CA for a falsified TPM key (such as an Attestation Key, DevID Key, or TLS authentication key), potentially enabling the falsification of other TPM 2.0 attestations with this key.
CVE-2026-67278.3 High
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
A timing side-channel issue in RSA OAEP decryption was reported in the TCG TPM 2.0 reference code that could allow a local attacker with elevated privileges to decrypt ciphertexts (such as import blobs, credential blobs, and session salts) encrypted to the RSA Endorsement Key, or potentially enable falsification of TPM 2.0 Attestation Keys.

Findings:

Under specific conditions, these issues could affect the trust properties of TPM‑protected keys, potentially allowing attestation of keys that were not securely generated or stored by the TPM.

Additionally, sensitive materials protected by the TPM endorsement key could be exposed, which may weaken the security properties relied upon by TPM‑based authentication and trust services.

Affected products:

Supermicro BIOS in the client motherboards.

AMD Motherboard GenerationBIOS version with the fix
CARAM5-Mv 2.8
M11SDV-4/8C(T)-LN4FNot Affected
M12SWA-TFNot Affected
H13SAE-MFv 2.8
H13SRD-FNot Affected
H13SRE-FNot Affected
H13SRHNot Affected
H13SRA-FNot Affected
H13SRA-TFNot Affected

Remediation:

  • All affected Supermicro motherboard SKUs will require a BIOS update to mitigate this potential vulnerability.
  • Updated BIOS firmware has been created to mitigate this potential vulnerability. Supermicro is currently testing and validating affected products. Please check Release Notes for the resolution.