Skip to content
LatestOrcaRouter Launches Gated OrcaCyber Zero 1.5 Model for Security Analysis
Tech News

Sysadmins Patch Linux to Mitigate AMD Zen TLBI Erratum 1718 If Microcode Update Is Missing

System administrators can now apply a Linux kernel patch to mitigate AMD Zen CPU translation errors if updated microcode is unavailable on their servers.

Sysadmins Patch Linux to Mitigate AMD Zen TLBI Erratum 1718 If Microcode Update Is Missing
Illustration: Vector Update

Key points

  • Linux 7.3-rc7 includes a kernel-level workaround for AMD TLBI Erratum 1718.
  • The fix targets stale translation entries in certain Zen processors.
  • The workaround will be back-ported to older kernel versions for broader support.

System administrators managing servers with affected AMD Zen processors should update to Linux 7.3-rc7 or apply back-ported patches to mitigate a hardware defect. This kernel update provides a software layer of protection against Translation Lookaside Buffer Invalidate Instruction errors. The change ensures that stale translation entries do not compromise system integrity when updated CPU microcode is not present on the hardware.

In plain English

The Translation Lookaside Buffer acts as a high-speed cache for memory addresses in a computer processor. When this cache contains outdated or stale information, the system may reference incorrect memory locations. AMD identified a specific defect, labeled Erratum 1718, where the instruction used to invalidate these entries fails to clear them properly. This can lead to unpredictable behavior or security vulnerabilities in systems running on affected Zen-based CPUs.

The background

According to Phoronix, this specific hardware issue was previously addressed through CPU microcode updates provided by AMD. These microcode patches are low-level firmware instructions that correct processor behavior at the hardware level. However, not all systems can receive or successfully apply these microcode updates due to legacy hardware constraints or virtualization environments. For those systems, the lack of microcode updates left them exposed to the risks associated with stale translation entries.

What changes now

The Linux kernel development community has introduced a workaround within the 7.3-rc7 release to address this gap. This software-based mitigation allows the operating system to manage the translation buffer more safely, even when the underlying hardware microcode is outdated. Phoronix reports that this fix is not limited to the latest kernel version. The development team plans to back-port the workaround to prior kernel versions, ensuring that organizations running stable or older releases can also protect their infrastructure from this specific erratum.

What to do and how to stay safe: Linux

  • Verify if your servers are running on AMD Zen processors that are subject to TLBI Erratum 1718.
  • Check your current CPU microcode version to determine if the hardware-level fix is already applied.
  • If microcode updates are unavailable, plan to upgrade to Linux 7.3-rc7 or a back-ported kernel version.
  • Monitor vendor advisories for confirmation of the back-port availability for your specific kernel release.

General security guidance from the Vector Update newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

What is AMD TLBI Erratum 1718?

It is a hardware defect in certain AMD Zen CPUs where the Translation Lookaside Buffer Invalidate Instruction may fail to clear stale translation entries.

Do I need to update my CPU microcode?

Updating CPU microcode is the primary fix, but the Linux kernel workaround is available for systems that cannot receive or apply the microcode update.

Will this fix be available for older Linux versions?

Yes, according to Phoronix, the kernel workaround introduced in Linux 7.3-rc7 will be back-ported to prior kernel versions.

Sources

  1. Phoronix
LinuxAMDKernelTLBIErratum 1718

Related stories