home.social

#zenbleed — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #zenbleed, aggregated by home.social.

fetched live
  1. #AMD discloses slew of high severity #security #vulnerabilities for #Zen systems, from the original Zen chips to the latest #Zen4 #CPU, that attacks #BIOS chips, we finally have a #Zenbleed fix. AMD is patching the vulnerabilities through new versions of #AGESA, for #Zen2-based chips, in particular, many of these new AGESAs also patch Zenbleed, including #Epyc #Server chips bit.ly/3I1JKds tomshardware.com/pc-components

  2. Pretty good video to watch on the #zenbleed vulnerability, feat. Tacos Ormandy:
    youtu.be/neWc0H1k2Lc

  3. When looking at all the CPU vulnerabilities in the recent years even until this day. We see mitigations taking place in microcode or OS level. But the performance impact is huge! Sometimes 30%-50% decrease in performance on specific tasks like databases!
    Question: can we get some compensation as consumer? Since both Intel and AMD sold hardware that doesn't give the promised results.
    #specre #meltdown #hertzbleed #Zenbleed #Inception #vulnerability #security #secops #compensation #money

  4. I added a known-good microcode check to my #FreeBSD #Zenbleed MSR chicken-bit rc script, and a reminder to check it all again in mid-December.

    I don't have the relevant CPUs to hand to test it directly so do let me know how you get on.

    gist.github.com/Freaky/2560975

  5. @Violet This years #defcon looks ripe with CPU vulnerabilities.

    #Zenbleed last week for AMD

    today:
    #Downfall for Intel

    #Inception for AMD

  6. Maximum oof:

    > It took a bit of work, but I found a variant that can leak about 30 kb per core, per second.

    There's a nice clear explanation here: lock.cmpxchg8b.com/zenbleed.ht

    #zenbleed

  7. Unfortunately @theregister published misleading and incorrect information that using QEMU (i.e. KVM / Firecracker) mitigates the AMD #Zenbleed exploit.

    _It does not_

    We demo the exploit in a GitHub Action and show how to mitigate it.
    actuated.dev/blog/amd-zenbleed

    #bot
    Original tweet : nitter.it/alexellisuk/status/1

  8. FIxes for AMD 'Zenbleed' CVE-2023-20593 has landed in Debian archives. For stable (bookworm), vulnerability is fixed in Linux version 6.1.38-2 and for old-stable (bullseye) fix is in version 5.10.179-3.

    This only fixes for 2nd gen Epyc CPUs, further CPUs to follow in later releases. Please update your Debian (and downstream) servers.

    #debian #zenbleed #hopbox

  9. Eine neu entdeckte Sicherheitslücke bedroht zahlreiche -AMD-Prozessoren. Die meisten Patches kommen erst in Richtung Jahresende. #Zenbleed winfuture.de/news,137655.html?

  10. #Debian has released a mitigation for the #zenbleed vulnerability CVE-2023-20593: "[DSA 5461-1] linux security update"

    This kernel update will identify if the CPU is affected (and no microcode update has been installed) and enable the "chicken bit" if needed.

    lists.debian.org/debian-securi

  11. July Security Updates! 🚀

    This one is rather crucial is you are running AMD EPYC CPUs, due to a fix in #zenbleed via a CPU microcode update.

    Read the details here:

    xcp-ng.org/blog/2023/07/27/jul

  12. We have seen a ton of testing and no reported errors, so we are releasing our patches tomorrow at 7am eastern US time. Get the details and join the conversation here: almalinux.discourse.group/t/ze

  13. @deutrino

    Just this week I had reflected on how #AMD #Zen processors are in most of the current generation of #VideoGame systems (other than Nintendo Switch).

    syncopate.us/articles/2007/b02

    Until the #ZenBleed exploit can be neutralized, better not browse web sites on those systems.

    #InfoSec

  14. "🎯 Zenbleed: A Serious Bug in AMD Processors 🐞"

    Zenbleed, a silicon-level bug in AMD processors, can be exploited to steal passwords, cryptographic keys, and more. Patch up when you can!

    Source: nakedsecurity.sophos.com/2023/

    Tags: #Zenbleed #AMD #ProcessorVulnerability #Cybersecurity #PatchUp 💻🔐

  15. Here's an rc script for #FreeBSD to apply (and remove) the #Zenbleed MSR "chicken bit" workaround.

    Simply drop in /usr/local/etc/rc.d/zenbleed_workaround, run `service zenbleed_workaround enable` and then `service zenbleed_workaround start`.

    gist.github.com/Freaky/2560975

  16. Jetzt können wir euch auch verraten, was der Grund für die ungeplanten Wartungsarbeiten gestern und heute war:

    Ja, das waren die Kernel- und Microcode-Updates für #zenbleed.

    Wir haben den veröffentlichten PoC-Code auch einmal auf einem Test-System ausprobiert.

    Das funktioniert erstaunlich... gut.

    Insofern: Sofern ihr eigene Systeme betreibt, bitte dringend updaten!