Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Ryzenfall, Chimera and Fallout were names for 13 vulnerabilities publicly disclosed by CTS-Labs on March 13, 2018. They were grouped into four families—Masterkey, Ryzenfall, Fallout and Chimera—and affected different layers of some AMD platforms. Ryzenfall and Fallout involved firmware running on AMD’s Platform Security Processor (PSP), while Chimera concerned selected chipsets. The reported consequences included access to memory normally protected from the operating system and, in the most serious cases, code execution with higher privileges.

These were not described as unauthenticated remote attacks. CERT-FR said exploitation required the attacker to run code with privileged access; Masterkey additionally required the ability to rewrite BIOS flash. Whether an old motherboard is patched is a model-and-BIOS question, not something the 2018 disclosure alone can answer.

What was disclosed in March 2018?

CTS-Labs announced 13 vulnerabilities affecting recent AMD x86 processors on March 13, 2018. The announcement named Ryzenfall, Chimera and Fallout, but the complete grouping also included Masterkey. CERT-FR’s March 23, 2018 bulletin said AMD had received notice only 24 hours before public disclosure and criticized the initial lack of technical detail.

CERT-FR later reported that independent firms and researchers who obtained the technical material confirmed the vulnerabilities, and that AMD acknowledged them and announced BIOS-based fixes. The bulletin is a historical account of the findings and the response at that time; it is not a current compatibility list for every AMD system.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall

The four vulnerability families at a glance

Family Component described by CERT-FR Platform scope reported at the time Prerequisite noted in the bulletin Reported impact
Masterkey Firmware running on the AMD Platform Security Processor (also called the AMD Secure Processor) Recent AMD platforms covered by the disclosure; affected models were not all identical Privileged code execution, plus the ability to rewrite BIOS flash Arbitrary code execution on the PSP, with the possibility of persistent code outside normal operating-system controls
Ryzenfall PSP firmware Reported across affected Ryzen-family and other recent AMD platforms; the disclosure did not mean every Ryzen model was affected Privileged code execution Reading or writing memory segments normally unavailable to the operating system; in severe cases, execution in SMM or on the PSP
Fallout PSP firmware Reported on selected recent AMD platforms, including systems in the Ryzen and EPYC families as applicable to the specific flaw Privileged code execution Access to protected or reserved memory and potential higher-privilege execution
Chimera Selected chipsets designed with ASMedia, rather than the processor core itself AM4 and TR4 socket platforms in the reported scope; NVD’s CVE-2018-8935 record identifies the Promontory chipset and the label “CHIMERA-HW” Dependent on the particular chipset weakness and a foothold on the system Chipset-level vulnerabilities that could permit code execution or undermine platform protections, depending on the specific issue

The table describes the 2018 report, not a present-day vulnerability matrix. A processor generation, socket or product family alone is insufficient to determine whether a particular board was affected.

Why the Platform Security Processor mattered

The PSP is a dedicated security processor embedded in many AMD platforms. It handles security-sensitive operations below the normal operating-system layer, including parts of platform initialization and trusted execution. A flaw in PSP firmware is therefore different from an ordinary application bug: successful exploitation could reach memory or execution contexts that Windows, Linux or another operating system is not supposed to control.

CERT-FR described Ryzenfall and Fallout as allowing reads or writes to memory that was initially inaccessible to the operating system. The protected regions could include memory used by hardware virtualization, System Management Mode (SMM), or memory reserved for the PSP. In the most serious descriptions, an attacker could execute code in SMM or on the PSP itself.

Chimera had a different boundary. It concerned selected AMD chipsets developed in collaboration with ASMedia and used with AM4 and TR4 sockets. The National Vulnerability Database entry for CVE-2018-8935 associates the Promontory chipset used in AMD Ryzen and Ryzen Pro platforms with “CHIMERA-HW.” That record should not be generalized to every AMD chipset or every Ryzen-branded product.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What an attacker needed

The historical advisory is important about prerequisites. CERT-FR stated: “Pour exploiter l’ensemble de ces vulnérabilités, il est nécessaire de pouvoir exécuter du code à un niveau privilégié.” In English: exploiting all of these vulnerabilities requires the ability to execute code at a privileged level.

  • Privileged execution was required. The bulletin described a post-compromise escalation path, not a simple unauthenticated attack from the internet.
  • Masterkey had an additional condition: the attacker needed the capability to rewrite the BIOS flash.
  • The impact could be stealthy and persistent. Code operating in PSP firmware, SMM or another below-OS context may not be visible to ordinary endpoint tools and can survive actions that only reinstall the operating system.

Those conditions do not make the flaws harmless. They mean the realistic security question was whether an attacker had already gained a privileged foothold or control of firmware-update mechanisms. The bulletin does not establish that every affected machine was equally exposed, nor that every system remains vulnerable today.

Ryzenfall, Fallout and Chimera versus Spectre and Meltdown

Ryzenfall, Fallout and Chimera were often discussed alongside Spectre and Meltdown because the disclosures were close in time, but they were not the same class of issue. CERT-FR explicitly separated the PSP and chipset vulnerabilities from the speculative-execution attacks. Spectre and Meltdown concerned CPU speculative-execution behavior; the families in this report concerned PSP firmware or selected chipset components.

How the disclosure and response unfolded

  1. March 13, 2018: CTS-Labs publicly announced 13 vulnerabilities affecting recent AMD x86 processors, according to CERT-FR.
  2. Before publication: CERT-FR said AMD had been notified about 24 hours before the public announcement.
  3. After technical details circulated: CERT-FR reported that multiple companies and independent researchers who obtained the material confirmed the vulnerabilities. AMD acknowledged the findings and announced fixes delivered through BIOS updates.
  4. March 23, 2018: CERT-FR stated that the announced AMD BIOS fixes were not yet available. That was a point-in-time observation and does not describe current BIOS availability.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Did AMD patch the flaws?

AMD’s stated mitigation path was firmware distributed through BIOS updates from motherboard and system manufacturers. The current AMD Product Security index is useful for locating vendor advisories, but its inspected text does not list “Ryzenfall” or “CTS Labs” and cannot establish whether a particular legacy board received a fix.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To check an individual computer:

  1. Identify the exact motherboard or system model, not merely the processor name. On a prebuilt PC or laptop, use the manufacturer’s model designation; on a self-built desktop, record the motherboard model and revision.
  2. Record the installed BIOS/UEFI revision from the firmware setup screen or the operating system’s system-information panel.
  3. Open the manufacturer’s support page for that exact model and compare the installed revision with the latest BIOS or firmware release notes.
  4. Look for security fixes, PSP/AMD Secure Processor updates, or a statement that the release incorporates AMD security advisories. Do not assume that the newest release for a different board in the same socket family applies to yours.
  5. Follow the manufacturer’s flashing instructions and recovery requirements. Keep power stable during the update, and do not use a BIOS image intended for another model or board revision.

If the manufacturer no longer provides firmware for the board, the public 2018 announcement cannot tell you whether an unpatched issue remains. In that situation, document the last supported BIOS, apply all available operating-system and security controls, and ask the OEM or board vendor for a model-specific status.

Who should be especially careful about the model caveat?

  • AM4 and TR4 desktop owners: Chimera’s reported scope involved selected chipsets, so socket compatibility alone does not establish exposure.
  • Ryzen and Ryzen Pro owners: The Promontory reference in the NVD entry applies to the specific chipset context identified there, not every Ryzen system.
  • Ryzen Mobile and EPYC owners: Some reported PSP issues were associated with broader recent-platform categories, but the affected SKU and firmware combinations varied. Verify the exact system or server model.
  • Virtualization and high-assurance environments: The reported ability to reach memory used by virtualization, SMM or the PSP makes vendor firmware status particularly important.

What the report does—and does not—prove today

The 2018 evidence supports a clear historical conclusion: AMD’s PSP firmware and certain chipsets contained serious design or implementation flaws that could become powerful post-compromise escalation mechanisms. It does not prove that an attacker can remotely compromise an unprivileged, fully updated PC; that every Ryzen-branded processor is affected; or that every old motherboard received the same BIOS fix.

For a current risk decision, the decisive evidence is the firmware record for the exact motherboard, laptop, workstation or server. Treat the CTS-Labs names as a prompt to verify that record, not as a substitute for it.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.