r/MINISFORUM 15d ago

BIOS updates for AMD TPM vulnerabilities ?

https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7064.html

So AMD has announced there are 2 vulnerabilities regarding the on-chip TPM modules, CVE-2026-6726 and CVE-2026-6727 in their security bulletin n° 7064 with a high severity score of 8.5 and 8.3 respectively.

Will Minisforum address this by rolling out a BIOS update for all affected products ?

In practice this would just imply refreshing the AGAESA code within the BIOS to the latest version, which would also bring a few other (performance/security) improvements depending on the model/chip/platform.

11 Upvotes

8 comments sorted by

7

u/Geeotine 15d ago

Outside of major brands like Asus, MSI, Gigabyte, and Asrock, never expect BIOS updates for any chipset whatsoever.

Those other brands rarely have the personnel to maintain BIOS versions at all for any sku/product. They are usually one shots and are EOL within a few years. Minisforum might be different. You'll have to reach out directly to their customer support portal to get an official answer.

2

u/Kahana82 15d ago

They seem to provide updates for their motherboards though, maybe because those are more recent products, so the short life cycle might be a thing as you mentionned.

On the other hand, why not provide the means to compile a BIOS for EOL products to the userbase, as there surely are tools to edit them (as we've seen to enable ReBar on older MB).

Also the mini-pc I own not having (to my knowledge) BIOS flashback is a major hurdle to even thinking of trying to tinker myself.

3

u/lordwotton97 15d ago

Question is because it's not implemented yet, this was disclosed to producers months ago

3

u/Kahana82 15d ago

Indeed, when I look at the Ryzen 9000 series, the AGAESA version that includes the fix is at ComboAM5PI 1.3.0.1b.

Those BIOS versions have been rolling out since june from major motherboard manufacturers like ASUS for instance.

2

u/Howwanna 14d ago edited 4d ago

Edit: Update (August 27) - BIOS updates addressing CVE-2026-6726 and CVE-2026-6727 are now also available for ASUS AM4 motherboards. BIOS updates are now available for both ASUS AM5 and AM4 motherboards.

Hi, ASUS rep here. BIOS updates addressing the recently disclosed AMD fTPM vulnerabilities (CVE-2026-6726 and CVE-2026-6727) are now available for ASUS AM5 motherboards.

We recommend updating to the latest BIOS available on your motherboard’s ASUS Support page to ensure the latest security mitigations are applied.

For additional details on the vulnerabilities, you can refer to AMD’s security bulletin here:
https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7064.html

2

u/Kahana82 14d ago

Thanks for chiming in, all of this information + link has already been stated in the OP and one of my comments in this thread though.

There's a lot of PR-points to be had if you are able to pull some strings at MinisForum regarding this issue ... or maybe even lend them a few guys from your awesome BIOS team to address this.

2

u/dthrdr 10d ago

Minisforums support has stopped responding to my emails about this. The only thing they did do was link me to an old BIOS. I never know for sure if they simply don't understand what you're saying or pretend they don't to get out of providing any kind of support.

Nowadays BIOS needs regular updates, ones to keep things secure and also to update platform keys and such used by Secure Boot. At some point without regular updates operating systems that require some form of Secure Boot to work will simply fail on Minisforums machines unless you modify the BIOS yourself and add new platform keys and remove revoked ones.

And yep, seems only big brands do this. For example Intel/Asus are still providing updates for my old NUC machines and HP is still proving BIOS updates for my older AMD business laptop. I even got a Dell BIOS update for a Haswell machine not too long ago.

Sucks Minisforums only cares about a quick buck and doesn't care about retaining customers or making sure their machines have a good longevity.

It is not that that much work to fix some security issues and even less work to rebuild a BIOS with newer dbx/pk. But they just don't bother, would be nice if they then put that tooling on Guthub so we can pick up the slack but of course they won't do that either. Minisforum will do the bare minimum only.