Zenbleed attack leaks sensitive data from AMD Zen2 processors

Teilen:

Google’s security researcher Tavis Ormandy discovered a new vulnerability impacting AMD Zen2 CPUs that could allow a malicious actor to steal sensitive data, such as passwords and encryption keys, at a rate of 30KB/sec from each CPU core.

The vulnerability is tracked as CVE-2023-20593 and is caused by the improper handling of an instruction called ‘vzeroupper’ during speculative execution, a common performance-enhancing technique used in all modern processors.

Ormandy used fuzzing and performance counters to discover specific hardware events and validated his results using an approach called “Oracle Serialization.”

With this approach, the author was able to detect inconsistencies between the execution of the randomly generated program and its serialized oracle, leading to the discovery of CVE-2023-20593 in Zen2 CPUs.

After triggering an optimized exploit for the flaw, the researcher could leak sensitive data from any system operation, including those that take place in virtual machines, isolated sandboxes, containers, etc.

“It took a bit of work, but I found a variant that can leak about 30 kb per core, per second. This is fast enough to monitor encryption keys and passwords as users login!,” explained Ormandy in a technical write-up of the flaw.

First big result from our new CPU research project, a use-after-free in AMD Zen2 processors! AMD have just released updated microcode for affected systems, please update! https://t.co/NVPWFpVopz pic.twitter.com/HgKwu9w8Av

The researcher reported the flaw to AMD on May 15, 2023, and today, he published a proof-of-concept (PoC) exploit for CVE-2023-20593.

The exploit is written for Linux, but the bug is OS-agnostic, so all operating systems running on Zen 2 CPUs are affected.

The flaw impacts all AMD CPUs built on the Zen 2 architecture, including the Ryzen 3000 (“Matisse”), Ryzen 4000U/H (“Renoir”), Ryzen 5000U (“Lucienne”), Ryzen 7020, and the high-end ThreadRipper 3000 and Epyc server (“Rome”) processors.

If your CPU is impacted by ‘Zenbleed,’ it is recommended to apply AMD’s new microcode update or wait for your computer vendor to incorporate the fix in a future BIOS upgrade.

Alternatively, the researcher proposes the mitigation method of setting the “chicken bit” to DE_CFG[9], although this workaround would result in a CPU performance drop.

Ormandy concludes that detecting exploitation of Zenbleed is most likely impossible, as improper usage of ‘vzeroupper’ does not require elevated privileges or special system calls and hence would be pretty stealthy.

Zenbleed’s practical impact on regular users is relatively low, as it requires local access to the target system and a high degree of specialization and knowledge to exploit.

However, it’s essential to keep systems up-to-date with the latest security patches and apply any BIOS updates as soon as they become available.

 

(c) Sergiu Gatlan

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
2:45 pm, Mai 18, 2025
Wetter-Symbol 16°C
L: 14° | H: 18°
wenige Wolken
Luftfeuchtigkeit: 60 %
Druck: 1019 mb
Wind: 3 mph WNW
Windböe: 6 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 13%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:04 am
Sonnenuntergang: 8:49 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
14° | 18°°C 0 mm 0% 7 mph 63 % 1020 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 11 mph 82 % 1022 mb 0 mm/h
Di. Mai 20 10:00 pm
Wetter-Symbol
9° | 20°°C 0 mm 0% 8 mph 79 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
12° | 18°°C 1 mm 100% 9 mph 93 % 1019 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
9° | 17°°C 0 mm 0% 10 mph 63 % 1023 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 7 mph 57 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
16° | 17°°C 0 mm 0% 6 mph 55 % 1019 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 14°°C 0 mm 0% 6 mph 63 % 1020 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 7 mph 69 % 1020 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 82 % 1020 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
12° | 12°°C 0 mm 0% 7 mph 73 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 8 mph 51 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 45 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,209.40
1.15%
Ethereum(ETH)
€2,253.09
2.02%
Fesseln(USDT)
€0.90
-0.01%
XRP(XRP)
€2.14
2.50%
Solana(SOL)
€153.79
2.93%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.201109
5.12%
Shiba Inu(SHIB)
€0.000013
4.76%
Pepe(PEPE)
€0.000012
8.68%
Peanut das Eichhörnchen(PNUT)
€0.307051
15.80%
Nach oben scrollen