home.social

#zenbleed — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zenbleed, aggregated by home.social.

fetched live
  1. #AMD discloses slew of high severity #security #vulnerabilities for #Zen systems, from the original Zen chips to the latest #Zen4 #CPU, that attacks #BIOS chips, we finally have a #Zenbleed fix. AMD is patching the vulnerabilities through new versions of #AGESA, for #Zen2-based chips, in particular, many of these new AGESAs also patch Zenbleed, including #Epyc #Server chips bit.ly/3I1JKds tomshardware.com/pc-components

  2. #AMD discloses slew of high severity #security #vulnerabilities for #Zen systems, from the original Zen chips to the latest #Zen4 #CPU, that attacks #BIOS chips, we finally have a #Zenbleed fix. AMD is patching the vulnerabilities through new versions of #AGESA, for #Zen2-based chips, in particular, many of these new AGESAs also patch Zenbleed, including #Epyc #Server chips bit.ly/3I1JKds tomshardware.com/pc-components

  3. discloses slew of high severity for systems, from the original Zen chips to the latest , that attacks chips, we finally have a fix. AMD is patching the vulnerabilities through new versions of , for -based chips, in particular, many of these new AGESAs also patch Zenbleed, including chips bit.ly/3I1JKds tomshardware.com/pc-components

  4. #AMD discloses slew of high severity #security #vulnerabilities for #Zen systems, from the original Zen chips to the latest #Zen4 #CPU, that attacks #BIOS chips, we finally have a #Zenbleed fix. AMD is patching the vulnerabilities through new versions of #AGESA, for #Zen2-based chips, in particular, many of these new AGESAs also patch Zenbleed, including #Epyc #Server chips bit.ly/3I1JKds tomshardware.com/pc-components

  5. #AMD discloses slew of high severity #security #vulnerabilities for #Zen systems, from the original Zen chips to the latest #Zen4 #CPU, that attacks #BIOS chips, we finally have a #Zenbleed fix. AMD is patching the vulnerabilities through new versions of #AGESA, for #Zen2-based chips, in particular, many of these new AGESAs also patch Zenbleed, including #Epyc #Server chips bit.ly/3I1JKds tomshardware.com/pc-components

  6. Pretty good video to watch on the #zenbleed vulnerability, feat. Tacos Ormandy:
    youtu.be/neWc0H1k2Lc

  7. Pretty good video to watch on the #zenbleed vulnerability, feat. Tacos Ormandy:
    youtu.be/neWc0H1k2Lc

  8. Pretty good video to watch on the #zenbleed vulnerability, feat. Tacos Ormandy:
    youtu.be/neWc0H1k2Lc

  9. Pretty good video to watch on the #zenbleed vulnerability, feat. Tacos Ormandy:
    youtu.be/neWc0H1k2Lc

  10. When looking at all the CPU vulnerabilities in the recent years even until this day. We see mitigations taking place in microcode or OS level. But the performance impact is huge! Sometimes 30%-50% decrease in performance on specific tasks like databases!
    Question: can we get some compensation as consumer? Since both Intel and AMD sold hardware that doesn't give the promised results.
    #specre #meltdown #hertzbleed #Zenbleed #Inception #vulnerability #security #secops #compensation #money

  11. When looking at all the CPU vulnerabilities in the recent years even until this day. We see mitigations taking place in microcode or OS level. But the performance impact is huge! Sometimes 30%-50% decrease in performance on specific tasks like databases!
    Question: can we get some compensation as consumer? Since both Intel and AMD sold hardware that doesn't give the promised results.
    #specre #meltdown #hertzbleed #Zenbleed #Inception #vulnerability #security #secops #compensation #money

  12. When looking at all the CPU vulnerabilities in the recent years even until this day. We see mitigations taking place in microcode or OS level. But the performance impact is huge! Sometimes 30%-50% decrease in performance on specific tasks like databases!
    Question: can we get some compensation as consumer? Since both Intel and AMD sold hardware that doesn't give the promised results.
    #specre #meltdown #hertzbleed #Zenbleed #Inception #vulnerability #security #secops #compensation #money

  13. When looking at all the CPU vulnerabilities in the recent years even until this day. We see mitigations taking place in microcode or OS level. But the performance impact is huge! Sometimes 30%-50% decrease in performance on specific tasks like databases!
    Question: can we get some compensation as consumer? Since both Intel and AMD sold hardware that doesn't give the promised results.
    #specre #meltdown #hertzbleed #Zenbleed #Inception #vulnerability #security #secops #compensation #money

  14. When looking at all the CPU vulnerabilities in the recent years even until this day. We see mitigations taking place in microcode or OS level. But the performance impact is huge! Sometimes 30%-50% decrease in performance on specific tasks like databases!
    Question: can we get some compensation as consumer? Since both Intel and AMD sold hardware that doesn't give the promised results.
    #specre #meltdown #hertzbleed #Zenbleed #Inception #vulnerability #security #secops #compensation #money

  15. I added a known-good microcode check to my #FreeBSD #Zenbleed MSR chicken-bit rc script, and a reminder to check it all again in mid-December.

    I don't have the relevant CPUs to hand to test it directly so do let me know how you get on.

    gist.github.com/Freaky/2560975

  16. I added a known-good microcode check to my #FreeBSD #Zenbleed MSR chicken-bit rc script, and a reminder to check it all again in mid-December.

    I don't have the relevant CPUs to hand to test it directly so do let me know how you get on.

    gist.github.com/Freaky/2560975

  17. I added a known-good microcode check to my MSR chicken-bit rc script, and a reminder to check it all again in mid-December.

    I don't have the relevant CPUs to hand to test it directly so do let me know how you get on.

    gist.github.com/Freaky/2560975

  18. I added a known-good microcode check to my #FreeBSD #Zenbleed MSR chicken-bit rc script, and a reminder to check it all again in mid-December.

    I don't have the relevant CPUs to hand to test it directly so do let me know how you get on.

    gist.github.com/Freaky/2560975

  19. @Violet This years #defcon looks ripe with CPU vulnerabilities.

    #Zenbleed last week for AMD

    today:
    #Downfall for Intel

    #Inception for AMD

  20. @Violet This years #defcon looks ripe with CPU vulnerabilities.

    #Zenbleed last week for AMD

    today:
    #Downfall for Intel

    #Inception for AMD

  21. @Violet This years #defcon looks ripe with CPU vulnerabilities.

    #Zenbleed last week for AMD

    today:
    #Downfall for Intel

    #Inception for AMD

  22. @Violet This years #defcon looks ripe with CPU vulnerabilities.

    #Zenbleed last week for AMD

    today:
    #Downfall for Intel

    #Inception for AMD

  23. @Violet This years #defcon looks ripe with CPU vulnerabilities.

    #Zenbleed last week for AMD

    today:
    #Downfall for Intel

    #Inception for AMD

  24. Maximum oof:

    > It took a bit of work, but I found a variant that can leak about 30 kb per core, per second.

    There's a nice clear explanation here: lock.cmpxchg8b.com/zenbleed.ht

    #zenbleed

  25. Maximum oof:

    > It took a bit of work, but I found a variant that can leak about 30 kb per core, per second.

    There's a nice clear explanation here: lock.cmpxchg8b.com/zenbleed.ht

    #zenbleed

  26. Maximum oof:

    > It took a bit of work, but I found a variant that can leak about 30 kb per core, per second.

    There's a nice clear explanation here: lock.cmpxchg8b.com/zenbleed.ht

    #zenbleed

  27. Maximum oof:

    > It took a bit of work, but I found a variant that can leak about 30 kb per core, per second.

    There's a nice clear explanation here: lock.cmpxchg8b.com/zenbleed.ht

    #zenbleed

  28. Haven't seen it mentioned much #zenbleed is a new vulnerability found on Zen 2 processors, surrounding speculative execution.

    https://lock.cmpxchg8b.com/zenbleed.html

  29. Unfortunately @theregister published misleading and incorrect information that using QEMU (i.e. KVM / Firecracker) mitigates the AMD #Zenbleed exploit.

    _It does not_

    We demo the exploit in a GitHub Action and show how to mitigate it.
    actuated.dev/blog/amd-zenbleed

    #bot
    Original tweet : nitter.it/alexellisuk/status/1

  30. Unfortunately @theregister published misleading and incorrect information that using QEMU (i.e. KVM / Firecracker) mitigates the AMD #Zenbleed exploit.

    _It does not_

    We demo the exploit in a GitHub Action and show how to mitigate it.
    actuated.dev/blog/amd-zenbleed

    #bot
    Original tweet : nitter.it/alexellisuk/status/1

  31. Unfortunately @theregister published misleading and incorrect information that using QEMU (i.e. KVM / Firecracker) mitigates the AMD #Zenbleed exploit.

    _It does not_

    We demo the exploit in a GitHub Action and show how to mitigate it.
    actuated.dev/blog/amd-zenbleed

    #bot
    Original tweet : nitter.it/alexellisuk/status/1

  32. Unfortunately @theregister published misleading and incorrect information that using QEMU (i.e. KVM / Firecracker) mitigates the AMD #Zenbleed exploit.

    _It does not_

    We demo the exploit in a GitHub Action and show how to mitigate it.
    actuated.dev/blog/amd-zenbleed

    #bot
    Original tweet : nitter.it/alexellisuk/status/1

  33. Unfortunately @theregister published misleading and incorrect information that using QEMU (i.e. KVM / Firecracker) mitigates the AMD #Zenbleed exploit.

    _It does not_

    We demo the exploit in a GitHub Action and show how to mitigate it.
    actuated.dev/blog/amd-zenbleed

    #bot
    Original tweet : nitter.it/alexellisuk/status/1

  34. FIxes for AMD 'Zenbleed' CVE-2023-20593 has landed in Debian archives. For stable (bookworm), vulnerability is fixed in Linux version 6.1.38-2 and for old-stable (bullseye) fix is in version 5.10.179-3.

    This only fixes for 2nd gen Epyc CPUs, further CPUs to follow in later releases. Please update your Debian (and downstream) servers.

    #debian #zenbleed #hopbox

  35. FIxes for AMD 'Zenbleed' CVE-2023-20593 has landed in Debian archives. For stable (bookworm), vulnerability is fixed in Linux version 6.1.38-2 and for old-stable (bullseye) fix is in version 5.10.179-3.

    This only fixes for 2nd gen Epyc CPUs, further CPUs to follow in later releases. Please update your Debian (and downstream) servers.

    #debian #zenbleed #hopbox

  36. FIxes for AMD 'Zenbleed' CVE-2023-20593 has landed in Debian archives. For stable (bookworm), vulnerability is fixed in Linux version 6.1.38-2 and for old-stable (bullseye) fix is in version 5.10.179-3.

    This only fixes for 2nd gen Epyc CPUs, further CPUs to follow in later releases. Please update your Debian (and downstream) servers.

    #debian #zenbleed #hopbox

  37. FIxes for AMD 'Zenbleed' CVE-2023-20593 has landed in Debian archives. For stable (bookworm), vulnerability is fixed in Linux version 6.1.38-2 and for old-stable (bullseye) fix is in version 5.10.179-3.

    This only fixes for 2nd gen Epyc CPUs, further CPUs to follow in later releases. Please update your Debian (and downstream) servers.

    #debian #zenbleed #hopbox

  38. Eine neu entdeckte Sicherheitslücke bedroht zahlreiche -AMD-Prozessoren. Die meisten Patches kommen erst in Richtung Jahresende. #Zenbleed winfuture.de/news,137655.html?