CVE-2023-20593Zenbleed: Information Exposure via Error Message in AMD Zen2 CPUs

Severity
5.5MEDIUMNVD
OSV6.5
EPSS
5.9%
top 9.41%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 24
Latest updateDec 5

Description

An issue in “Zen 2” CPUs, under specific microarchitectural circumstances, may allow an attacker to potentially access sensitive information.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages11 packages

Debianlinux/linux_kernel< 5.10.179-3+3
Ubuntulinux/linux_kernel< 4.4.0-248.282+1
NVDxen/xen4 versions+3

Also affects: Debian Linux 10.0, 11.0, 12.0

Patches

🔴Vulnerability Details

17
OSV
linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities2023-12-05
OSV
linux-bluefield vulnerabilities2023-09-26
OSV
linux-ibm, linux-ibm-5.4 vulnerabilities2023-09-11
OSV
linux-azure, linux-azure-4.15 vulnerabilities2023-09-08
OSV
linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities2023-09-06

📋Vendor Advisories

24
Ubuntu
Linux kernel vulnerabilities2023-12-05
Chrome
Long Term Support Channel Update for ChromeOS: CVE-2023-205932023-10-06
Ubuntu
Linux kernel (BlueField) vulnerabilities2023-09-26
Ubuntu
Linux kernel (OEM) vulnerabilities2023-09-19
Ubuntu
Linux kernel (IBM) vulnerabilities2023-09-11

🕵️Threat Intelligence

2
Wiz
Zenbleed: cross-process infoleak vulnerability in AMD Zen 2 Processors - everything you need to know | Wiz Blog2023-07-26
Wiz
Zenbleed: cross-process infoleak vulnerability in AMD Zen 2 Processors - everything you need to know | Wiz Blog2023-07-26

💬Community

1
Bugzilla
CVE-2023-20593 hw: amd: Cross-Process Information Leak2023-06-27
CVE-2023-20593 — Zenbleed | cvebase