news.volyx.in

Zenbleed (lock.cmpxchg8b.com)

1283 points by loeg · 1129 days ago · 361 comments on HN

Article summary

A vulnerability known as Zenbleed, identified as CVE-2023-20593, affects all Zen 2 class processors from AMD, allowing attackers to leak sensitive information such as encryption keys and passwords. The bug is related to the handling of the vzeroupper instruction and can be exploited through precise scheduling. AMD has released a microcode update to fix the issue. The vulnerability can be mitigated with a software workaround, but it is recommended to apply the microcode update for full protection.

Main themes

  • Zenbleed vulnerability
  • AMD processor security
  • BIOS updates and risks
  • Microcode patches
  • CPU architecture
  • Exploit mitigation
  • Processor security risks

What commenters say

  • Some commenters believe that flashing the BIOS is not as risky as it used to be, thanks to modern systems and UPS protection.
  • Others argue that a UPS is essential for safety and preventing damage from power outages and surges.
  • There is confusion about which AMD processors are affected by the Zenbleed vulnerability, with some clarifying that it only affects Zen 2 architecture.
  • The exploit may not work on all Zen 2 processors, and some users have reported being unable to reproduce the issue on their systems.
  • Some users are relieved to find that their Zen 3-based processors are not vulnerable to the exploit.
  • Others note that even if a user's processor is not vulnerable, they may still be running untrusted workloads, such as JavaScript in a browser, that could potentially be exploited.
  • The discussion also touches on the complexity of AMD's product lineup and the challenges of determining which processors are affected by the vulnerability.