AMD releases updates to mitigate the “Sinkclose” vulnerability but has no plans to update older Ryzen 1000, 2000, and 3000 or Threadripper 1000 and 2000 CPUs
which the company says it probably won't patch now Ashish Khaitan / The Cyber Express : Sinkclose Vulnerability in AMD Chips: What You Need to Know About Unpatched Models Jacob Roach / Digital Trends : Millions of AMD chips are being ignored in major security flaw fix Cheyenne MacDonald / Engadget : Outdated AMD chips reportedly won't get a patch for the ‘Sinkclose’ security flaw Forums: r/Amd : AMD won't patch all chips affected by severe data theft vulnerability — Ryzen 3000, 2000, and 1000 will not get patched for ‘Sinkclose’ r/hardware : AMD won't patch all chips affected by severe data theft vulnerability — Ryzen 3000, 2000, and 1000 will not get patched for ‘Sinkclose’
Context & Ripple Effects
The Sinkclose disclosure established that the issue spans AMD chips across a long hardware history, rather than a narrow current-generation defect. AMD's response now draws a practical support boundary within that exposed installed base.
That boundary contrasts with AMD's earlier approach of making firmware updates available for Ryzen and EPYC during the Spectre response. It makes firmware-support duration, not just a chip's underlying exposure, central to how owners manage the issue.
First-order effects
- Owners of the named older Ryzen and Threadripper generations cannot rely on a new AMD mitigation for Sinkclose and must evaluate their remaining exposure through their own security controls or hardware plans.
- Supported AMD platforms receive the released mitigations, creating a clear split between patchable and unpatched systems following the researchers' disclosure of Sinkclose's broad AMD reach.
Second-order effects
- Organizations with mixed AMD fleets may need to inventory affected generations and prioritize older machines differently in security operations, since a uniform firmware-update response is unavailable.
- System vendors and IT buyers face a more explicit distinction between processor capability and ongoing firmware support when deciding whether to retain or replace older hardware.
Third-order effects
- If vendors increasingly limit fixes for older CPU generations, security-support lifecycles could become a more consequential procurement constraint alongside performance, cost, and power use.
- The case reinforces a structural reality of platform security: vulnerabilities discovered years after shipment can leave durable installed bases dependent on vendor patch-policy boundaries rather than technical exposure alone.
The trend: Processor security is becoming a lifecycle-management issue, with the value of installed hardware increasingly shaped by how long vendors maintain firmware mitigations.