Home / Component / CPU / AMD confirms ‘Zenbleed’ security issue, publishes timeline for fixes

AMD confirms ‘Zenbleed’ security issue, publishes timeline for fixes

A new security vulnerability has been discovered, impacting AMD Zen 2 processors. The bug, known as Zenbleed, can be used to steal sensitive data, but mitigations for the exploit are already on the way.

An issue with Zen 2 processors means that under “specific microarchitectural circumstances”, a register in these processors may not be written to 0 correctly. This in turn can cause data from another process or thread to be stored in the YMM register, which an attacker could potentially use to access sensitive information. Cloudflare's analysis claims that the bug doesn't require physical access to a system to exploit.

The bug was brought to AMD's attention by Google security researcher, Tavis Ormandy and the company is already working on fixes. These will be rolled out to users of all Zen 2 processors in the form of BIOS updates and newer firmware.

While fixes are in the works, it will be a while until they arrive. In AMD's security bulletin, it puts a timeline of between October and December 2023 for these updates to roll out. With that said, a microcode update for EPYC 7002 series processors is already available and applying the patch is recommended for all users.

Discuss on our Facebook page, HERE.

KitGuru Says: Fixes for this are on the way, although the timeline is a little long. Fortunately, it doesn't appear that anyone has successfully managed to exploit this bug outside of research environments. 

Become a Patron!

Check Also

New Intel Nova Lake-AX platform could rival AMD Strix Halo

The battle in the high-performance APU segment could soon get a new contender, as the …

We've noticed that you are using an ad blocker.

Thank you for visiting KitGuru. Our news and reviews teams work hard to bring you the latest stories and finest, in-depth analysis.

We want to be as informative as possible – and to help our readers make the best buying decisions. The mechanism we use to run our business and pay some of the best journalists in the world, is advertising.

If you want to support KitGuru, then please add www.kitguru.net to your ad blocking whitelist or disable your adblocking software. It really makes a difference and allows us to continue creating the kind of content you really want to read.

It is important you know that we don’t run pop ups, pop unders, audio ads, code tracking ads or anything else that would interfere with the KitGuru experience. Adblockers can actually block some of our free content, such as galleries!