AMD Security Bulletin:
Cross-Process Information Leak
Bulletin ID: AMD-SB-7008Potential Impact: Information disclosure
Severity: Medium
Summary
Under specific microarchitectural circumstances, a register in “Zen 2” CPUs may not be written to 0 correctly. This may cause data from another process and/or thread to be stored in the YMM register, which may allow an attacker to potentially access sensitive information.CVE Details
Refer to Glossary for explanation of termsCVE | Severity | CVE Description |
CVE-2023-20593 | Medium | An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information. |
Mitigation
AMD recommends applying the µcode patch listed below for AMD EPYC™ 7002 Processors, and applying BIOS updates that include the following AGESA™ firmware versions for other affected products. AMD plans to release to the Original Equipment Manufacturers (OEM) the AGESA™ versions on the target dates listed below. Please refer to your OEM for the BIOS update specific to your product.DATA CENTER
Mitigation detail Update to versions listed or higher | 2nd Gen AMD EPYC™ Processors “Rome” |
µcode | 0x0830107A |
AGESA™ firmware | RomePI 1.0.0.H |
DESKTOP
Mitigation details Update to versions listed or higher | AMD Ryzen™ 3000 Series Desktop Processors “Matisse” | AMD Ryzen™ 4000 Series Desktop Processors with Radeon™ Graphics “Renoir” AM4 |
AGESA™ firmware | ComboAM4v2PI_1.2.0.C (Target Dec 2023) ComboAM4PI_1.0.0.C (Target Dec 2023) | ComboAM4v2PI_1.2.0.C (Target Dec 2023) |
HIGH END DESKTOP (HEDT)
Mitigation details Update to versions listed or higher | AMD Ryzen™ Threadripper™ 3000 Series Processors “Castle Peak” HEDT |
AGESA™ firmware | CastlePeakPI-SP3r3 1.0.0.A (Target Oct 2023) |
WORKSTATION
Mitigation details Update to versions listed or higher | AMD Ryzen™ Threadripper™ PRO 3000WX Series Processors “Castle Peak” WS SP3 |
AGESA™ firmware | CastlePeakWSPI-sWRX8 1.0.0.C (Target Nov 2023) ChagallWSPI-sWRX8 1.0.0.7 (Target Dec 2023) |
MOBILE - AMD Ryzen™ Series
Mitigation details Update to versions listed or higher | AMD Ryzen™ 5000 Series Mobile Processors with Radeon™ Graphics “Lucienne” | AMD Ryzen™ 4000 Series Mobile Processors with Radeon™ Graphics “Renoir” | AMD Ryzen™ 7020 Series Processors “Mendocino” FT6 |
AGESA™ firmware | CezannePI-FP6_1.0.1.0 (Target Dec 2023) | RenoirPI-FP6_1.0.0.D (Target Nov 2023) | MendocinoPI-FT6_1.0.0.6 (Target Dec 2023) |
Acknowledgement
AMD thanks Tavis Ormandy of Google Information Security Engineering for reporting this issue and engaging in coordinated vulnerability disclosure.Revisions
Revision Date | Description |
2023-07-24 | Initial publication |
Read more:

AMD 'Zenbleed' Bug Leaks Data From Zen 2 Ryzen, EPYC CPUs: Most Patches Coming Q4 (Updated)
A huge Zen 2 leak requires a patch.
Last edited: