CVE-2013-6885
published 2013-11-29CVE-2013-6885: The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which…
PriorityP415medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.59%
45.1th percentile
The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.14.2-1 (bookworm) | linux 3.14.2-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.14.2-1 | 3.14.2-1 |
| linux | linux_kernel | >= 0 < 3.14.2-1 | 3.14.2-1 |
| linux | linux_kernel | >= 0 < 3.14.2-1 | 3.14.2-1 |
| linux | linux_kernel | >= 0 < 3.14.2-1 | 3.14.2-1 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pw98-hqj6-fw9c: The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory typ
ghsa_unreviewed·2022-05-17
CVE-2013-6885 [MEDIUM] GHSA-pw98-hqj6-fw9c: The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory typ
The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue.
Kernel
x86, cpu, amd: Add workaround for family 16h, erratum 793
kernel_security·2014-01-15·CVSS 4.7
CVE-2013-6885 [MEDIUM] x86, cpu, amd: Add workaround for family 16h, erratum 793
x86, cpu, amd: Add workaround for family 16h, erratum 793
This adds the workaround for erratum 793 as a precaution in case not
every BIOS implements it. This addresses CVE-2013-6885.
Erratum text:
[Revision Guide for AMD Family 16h Models 00h-0Fh Processors,
document 51810 Rev. 3.04 November 2013]
793 Specific Combination of Writes to Write Combined Memory Types and
Locked Instructions May Cause Core Hang
Description
Under a highly specific and detailed set of internal timing
conditions, a locked instruction may trigger a timing sequence whereby
the write to a write combined memory type is not flushed, causing the
locked instruction to stall indefinitely.
Potential Effect on System
Processor core hang.
Suggested Workaround
BIOS should set MSR
C001_1020[15] = 1b.
Fix Planned
No
OSV
CVE-2013-6885: The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory typ
osv·2013-11-29·CVSS 4.7
CVE-2013-6885 [MEDIUM] CVE-2013-6885: The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory typ
The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue.
Red Hat
hw: AMD CPU erratum may cause core hang
vendor_redhat·2013-11-28·CVSS 4.7
CVE-2013-6885 [MEDIUM] CWE-1220 hw: AMD CPU erratum may cause core hang
hw: AMD CPU erratum may cause core hang
The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue.
Statement: This hardware issue is affecting certain AMD processors. Please consult your hardware vendor for any potential firmware updates providing a workaround for this issue.
Debian
CVE-2013-6885: linux - The microcode on AMD 16h 00h through 0Fh processors does not properly handle the...
vendor_debian·2013·CVSS 4.7
CVE-2013-6885 [MEDIUM] CVE-2013-6885: linux - The microcode on AMD 16h 00h through 0Fh processors does not properly handle the...
The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue.
Scope: local
bookworm: resolved (fixed in 3.14.2-1)
bullseye: resolved (fixed in 3.14.2-1)
forky: resolved (fixed in 3.14.2-1)
sid: resolved (fixed in 3.14.2-1)
trixie: resolved (fixed in 3.14.2-1)
No detection rules found.
No public exploits indexed.
http://lists.dragonflybsd.org/pipermail/kernel/2011-December/046594.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/123553.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/124195.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/124199.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2013/11/28/1http://rhn.redhat.com/errata/RHSA-2014-0285.htmlhttp://secunia.com/advisories/55840http://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://support.amd.com/TechDocs/51810_16h_00h-0Fh_Rev_Guide.pdfhttp://www.debian.org/security/2015/dsa-3128http://www.openwall.com/lists/oss-security/2013/12/02/1http://www.securityfocus.com/bid/63983http://www.securitytracker.com/id/1029415http://www.zdnet.com/blog/hardware/amd-owns-up-to-cpu-bug/18924https://bugzilla.redhat.com/show_bug.cgi?id=1035823https://exchange.xforce.ibmcloud.com/vulnerabilities/89335http://lists.dragonflybsd.org/pipermail/kernel/2011-December/046594.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/123553.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/124195.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-December/124199.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00021.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-04/msg00000.htmlhttp://openwall.com/lists/oss-security/2013/11/28/1http://rhn.redhat.com/errata/RHSA-2014-0285.htmlhttp://secunia.com/advisories/55840http://security.gentoo.org/glsa/glsa-201407-03.xmlhttp://support.amd.com/TechDocs/51810_16h_00h-0Fh_Rev_Guide.pdfhttp://www.debian.org/security/2015/dsa-3128http://www.openwall.com/lists/oss-security/2013/12/02/1http://www.securityfocus.com/bid/63983http://www.securitytracker.com/id/1029415http://www.zdnet.com/blog/hardware/amd-owns-up-to-cpu-bug/18924https://bugzilla.redhat.com/show_bug.cgi?id=1035823https://exchange.xforce.ibmcloud.com/vulnerabilities/89335
2013-11-29
Published