#zenbleed — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #zenbleed, aggregated by home.social.
-
#AMD discloses slew of high severity #security #vulnerabilities for #Zen systems, from the original Zen chips to the latest #Zen4 #CPU, that attacks #BIOS chips, we finally have a #Zenbleed fix. AMD is patching the vulnerabilities through new versions of #AGESA, for #Zen2-based chips, in particular, many of these new AGESAs also patch Zenbleed, including #Epyc #Server chips https://bit.ly/3I1JKds https://www.tomshardware.com/pc-components/cpus/amd-discloses-slew-of-high-severity-security-vulnerabilities-for-zen-chips-that-attack-bios-chips-updates-aim-to-patch-bugs-finally-fix-zenbleed
-
This Week in Security: 1Password, Polyglots, and Roundcube - This week we got news of a security incident at 1Password, and we’re certain we ar... - https://hackaday.com/2023/10/27/this-week-in-security-1password-polyglots-and-roundcube/ #hackadaycolumns #securityhacks #1password #roundcube #polyglot #zenbleed #news
-
Pretty good video to watch on the #zenbleed vulnerability, feat. Tacos Ormandy:
https://youtu.be/neWc0H1k2Lc -
When looking at all the CPU vulnerabilities in the recent years even until this day. We see mitigations taking place in microcode or OS level. But the performance impact is huge! Sometimes 30%-50% decrease in performance on specific tasks like databases!
Question: can we get some compensation as consumer? Since both Intel and AMD sold hardware that doesn't give the promised results.
#specre #meltdown #hertzbleed #Zenbleed #Inception #vulnerability #security #secops #compensation #money -
#Linux Kernel Updated To Add #Zenbleed Fix For Valve's #SteamDeck :steamdeck:
-
Ooopsie!
Linux Kernel Updated To Add Zenbleed Fix For Valve's Steam Deck - Phoronix https://www.phoronix.com/news/Linux-Zenbleed-Steam-Deck
#Linux #Kernel #Zenbleed #Fix #Valve #SteamDeck #AMD #Ryzen #Vulnerability #Hardware #GamingNews #TechNews
-
I added a known-good microcode check to my #FreeBSD #Zenbleed MSR chicken-bit rc script, and a reminder to check it all again in mid-December.
I don't have the relevant CPUs to hand to test it directly so do let me know how you get on.
https://gist.github.com/Freaky/2560975d3c94246b86f464b8be75c967
-
@Violet This years #defcon looks ripe with CPU vulnerabilities.
#Zenbleed last week for AMD
today:
#Downfall for Intel#Inception for AMD
-
Maximum oof:
> It took a bit of work, but I found a variant that can leak about 30 kb per core, per second.
There's a nice clear explanation here: https://lock.cmpxchg8b.com/zenbleed.html
-
Unfortunately @theregister published misleading and incorrect information that using QEMU (i.e. KVM / Firecracker) mitigates the AMD #Zenbleed exploit.
_It does not_
We demo the exploit in a GitHub Action and show how to mitigate it.
https://actuated.dev/blog/amd-zenbleed-update-now#bot
Original tweet : https://nitter.it/alexellisuk/status/1685952872125460480 -
FIxes for AMD 'Zenbleed' CVE-2023-20593 has landed in Debian archives. For stable (bookworm), vulnerability is fixed in Linux version 6.1.38-2 and for old-stable (bullseye) fix is in version 5.10.179-3.
This only fixes for 2nd gen Epyc CPUs, further CPUs to follow in later releases. Please update your Debian (and downstream) servers.
-
Eine neu entdeckte Sicherheitslücke bedroht zahlreiche -AMD-Prozessoren. Die meisten Patches kommen erst in Richtung Jahresende. #Zenbleed https://winfuture.de/news,137655.html?utm_source=Mastodon&utm_medium=ManualStatus&utm_campaign=SocialMedia
-
#Debian has released a mitigation for the #zenbleed vulnerability CVE-2023-20593: "[DSA 5461-1] linux security update"
This kernel update will identify if the CPU is affected (and no microcode update has been installed) and enable the "chicken bit" if needed.
https://lists.debian.org/debian-security-announce/2023/msg00153.html
-
This Week in Security: Zenbleed, Web Integrity, and More! - Up first is Zenbleed, a particularly worrying speculative execution bug, that unfo... - https://hackaday.com/2023/07/28/this-week-in-security-zenbleed-web-integrity-and-more/ #thisweekinsecurity #hackadaycolumns #securityhacks #zenbleed #ubuntu
-
July Security Updates! 🚀
This one is rather crucial is you are running AMD EPYC CPUs, due to a fix in #zenbleed via a CPU microcode update.
Read the details here:
https://xcp-ng.org/blog/2023/07/27/july-2023-security-update-zenbleed/
-
We have seen a ton of testing and no reported errors, so we are releasing our #Zenbleed patches tomorrow at 7am eastern US time. Get the details and join the conversation here: https://almalinux.discourse.group/t/zenbleed-patch-release-7am-eastern-us-time-7-27-23/2802 #linux
-
Just this week I had reflected on how #AMD #Zen processors are in most of the current generation of #VideoGame systems (other than Nintendo Switch).
http://syncopate.us/articles/2007/b02a
Until the #ZenBleed exploit can be neutralized, better not browse web sites on those systems.
-
"🎯 Zenbleed: A Serious Bug in AMD Processors 🐞"
Zenbleed, a silicon-level bug in AMD processors, can be exploited to steal passwords, cryptographic keys, and more. Patch up when you can!
Tags: #Zenbleed #AMD #ProcessorVulnerability #Cybersecurity #PatchUp 💻🔐
-
Here's an rc script for #FreeBSD to apply (and remove) the #Zenbleed MSR "chicken bit" workaround.
Simply drop in /usr/local/etc/rc.d/zenbleed_workaround, run `service zenbleed_workaround enable` and then `service zenbleed_workaround start`.
https://gist.github.com/Freaky/2560975d3c94246b86f464b8be75c967
-
Jetzt können wir euch auch verraten, was der Grund für die ungeplanten Wartungsarbeiten gestern und heute war:
Ja, das waren die Kernel- und Microcode-Updates für #zenbleed.
Wir haben den veröffentlichten PoC-Code auch einmal auf einem Test-System ausprobiert.
Das funktioniert erstaunlich... gut.
Insofern: Sofern ihr eigene Systeme betreibt, bitte dringend updaten!