×
Login Register an account
Top Submissions Explore Upgoat Search Random Subverse Random Post Colorize! Site Rules
14

AMD ‘Zenbleed’ exploit can leak passwords and encryption keys from Ryzen CPUs / Some patches are already rolling out, but updates for most impacted processors aren’t expected until late 2023.

submitted by dosvydanya_freedomz to technology 9 monthsJul 25, 2023 20:35:15 ago (+14/-0)     (www.theverge.com)

https://www.theverge.com/2023/7/25/23806705/amd-ryzen-cpu-processor-zenbleed-vulnerability-exploit-bug

A new vulnerability impacting AMD’s line of Zen 2 processors — which includes popular CPUs like the budget-friendly Ryzen 5 3600 — has been discovered that can be exploited to steal sensitive data like passwords and encryption keys. Google security researcher Tavis Ormandy disclosed the “Zenbleed” bug (filed as CVE-2023-20593) on his blog this week after first reporting the vulnerability to AMD on May 15th.


7 comments block


[ - ] drhitler 3 points 9 monthsJul 25, 2023 22:23:12 ago (+3/-0)

The attack does not require physical access to the computer or server and can even be executed via javascript on a webpage.

thats really fucked up, most of the times these "exploits" require have specific hard requirements that make the chances of the exploit being used against you rare

[ - ] dosvydanya_freedomz [op] 2 points 9 monthsJul 25, 2023 21:20:46 ago (+2/-0)

i bought a mini PC JUST THE other day and i had to return it because it crapped on me 10 days after use. bought it for my 9 year old nephew to play roblox and other light games.

amazon didnt want to replace it but they gave me a full refund which i use it to upgrade from a 1660ti to a rtx 3060

[ - ] lord_nougat 2 points 9 monthsJul 25, 2023 20:47:50 ago (+2/-0)

In fairness, it is already late 2023...

[ - ] Kozel 2 points 9 monthsJul 25, 2023 20:46:32 ago (+2/-0)

CVE-2023-20593 works on all Zen 2 class processors

full list of hardware: https://www.tomshardware.com/news/zenbleed-bug-allows-data-theft-from-amds-zen-2-processors-patches-released

doesn't look like my processor is affected

[ - ] lord_nougat 1 point 9 monthsJul 25, 2023 21:11:32 ago (+1/-0)

Well shit. My higher end Linux desktop appears to be effected. Luckily it is down due to ssd fail, so it can just stay down a little longer...

[ - ] o0shad0o 0 points 9 monthsJul 26, 2023 07:39:05 ago (+0/-0)

What appears to be a patch for this was released for Ubuntu yesterday.

[ - ] yesiknow 0 points 9 monthsJul 25, 2023 22:51:43 ago (+0/-0)

If we had any smart people, important information that can't be shared with others wouldn't be on a computer. We have nobody in government like that; smart.