PT-2023-3704 · Amd+10 · Amd Ryzen+11
Tavis Ormandy
·
Published
2023-07-24
·
Updated
2025-02-13
·
CVE-2023-20593
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
AMD Zen 2 processors (affected versions not specified)
Description
The issue in AMD Zen 2 processors, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. This is due to a use-after-free vulnerability, which can be exploited to track the contents of registers during the execution of other processes on the same CPU core. Researchers have found that 62% of AWS environments are potentially vulnerable to this issue, and it may affect various AMD Ryzen processors. The vulnerability can be used to steal confidential data, such as passwords and encryption keys.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability. However, AMD has begun releasing microcode updates, and clients are recommended to apply AGESA firmware fixes. As a temporary workaround, consider disabling or restricting the use of vulnerable components until a patch is available. Additionally, users can apply kernel-side mitigations to protect themselves until AMD releases fixed microcode updates for all affected CPUs.
Exploit
Generation of Error Message Containing Sensitive Information
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Amd Ryzen
Amd Zen 2
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu