Skip to content

ThePawn02

Gaming and Streaming Content

  • Blog
  • Editor's Picks
  • eSports
  • Guides
  • Headlines
  • News
  • Reviews
  • Uncategorized
  • Website Update
Primary Menu
  • Home
  • Watch Live
  • News
  • eSports
  • Blog
  • Reviews
  • Guides
  • Guild Login
    • Guild Mentality
    • The Zealots
    • Malign
  • Socials
    • Youtube Channel
    • Twitch Channel
    • Kick.com
    • Twitter
    • Instagram
    • Facebook
Subscribe
  • Home
  • 2023
  • July
  • AMD’s Zen 2 chips have a security bug that’s getting patched between now and 2024
  • News

AMD’s Zen 2 chips have a security bug that’s getting patched between now and 2024

Zenbleed shouldn't be left exposed for long, so you best keep an eye out for an upcoming AGESA fix for affected chips.
July 25, 2023 3 min read
AMD’s Zen 2 chips have a security bug that’s getting patched between now and 2024

Zenbleed shouldn't be left exposed for long, so you best keep an eye out for an upcoming AGESA fix for affected chips.

A security vulnerability has been uncovered in AMD processors built with the Zen 2 architecture. Spotted by a Google researcher, the so-called ‘Zenbleed’ vulnerability opens the door to a potential attacker and threatens the possibility of exposing sensitive information. Don’t worry, there is a fix, but us gamers will have to wait around a little longer than our server-side pals to get hold of it.

Zenbleed affects all Zen 2 processors, which includes Ryzen 3000/4000, Threadripper 3000, Ryzen 4000/5000/7020 mobile, and Epyc Rome generations.

The vulnerability, as described by AMD in a security bulletin, occurs “Under specific microarchitectural circumstances, a register in ‘Zen 2’ CPUs may not be written to 0 correctly. This may cause data from another process and/or thread to be stored in the YMM register, which may allow an attacker to potentially access sensitive information.”

The vulnerability is listed as “Medium” severity by AMD, however, its CVE (CVE-2023-20593) is not currently rated.

The vulnerabilities’ discoverer, Tavis Ormandy, goes into greater detail on how the exploit works in their blog post. They believe the reason they discovered the bug, as opposed to AMD in post-silicon validation, is because they don’t come from an electrical engineering background, oddly enough. They thank a technique called ‘fuzzing’ for sniffing the bug out, which is a way of testing out weird and unexpected data on a computer to expose unlikely architectural behaviours.

Ormandy notes that the vulnerability would work on your average machine but also virtual machines, sandboxes, containers, processors, “whatever!”

Clearly that’s a big deal for large cloud providers, who take security extremely seriously.

Speaking to Tom’s Hardware after they first noted the issue, AMD said it was not aware of any actual exploits outside of a research environment. It’s certainly appears unlikely that this vulnerability would pose a threat to your average gamer, and it’s more the cloud providers that will be worried about potential attacks than you or I, but this is the sort of vulnerability that is best patched up as soon as possible.

AMD was informed of the vulnerability on May 15, 2023, and since then has been working on mitigations.

Mitigations have already begun rolling out for Zenbleed, starting with the affected Epyc chips. We’ll see Threadripper chips patched up around October into December, depending on the model. Laptop Ryzen processors should begin being fixed around November/December this year.

(Image credit: AMD)

(Image credit: AMD)

Finally, desktop Ryzen processors will get patched likely around December this year. That’s a long time to wait for a patch, but at least this is the sort of mitigation that can be rolled out through microcode and AGESA updates—it wasn’t that long ago that hardware mitigations were needed to patch up side-channel attack vulnerabilities on some Intel processors as a result of the Spectre vulnerability, which affected many chips.

Though we haven’t yet any idea as to how these patches may affect performance. Mitigations can have an impact, though whether it’ll impact gaming isn’t known at this time. 

Your next machine

(Image credit: Future)

Best gaming PC: The top pre-built machines.
Best gaming laptop: Great devices for mobile gaming.

AMD has said to Tom’s Hardware: “Any performance impact will vary depending on workload and system configuration.”

That’s about as vague as it gets on the performance issue, though I wouldn’t fret about it just yet. Any performance issues will come out in the wash once the patch drops, and it’s possible there’s little to no noticeable impact on frame rates

The important thing will be to look out for that new AGESA firmware and get your system secured in case any nefarious ne’er do wells end up trying to take advantage of this exploit. For desktop chips, that’s ComboAM4v2PI_1.2.0.C or ComboAM4PI_1.0.0.C.

About Post Author

See author's posts

Continue Reading

Previous: Yoshi-P speaks out on Final Fantasy 16 toxicity: ‘There’s a lot of people who just yell at you’
Next: Remnant 2 review

Related News

Rematch launched without crossplay because of ‘unforeseen technical complexities’ and Sloclap is sorry, but it’s a hit on Steam anyway
3 min read
  • News

Rematch launched without crossplay because of ‘unforeseen technical complexities’ and Sloclap is sorry, but it’s a hit on Steam anyway

ThePawn.com June 19, 2025
Stellaris updates are going to start coming more slowly, because new patches are causing new problems and QA testers can’t keep up
2 min read
  • News

Stellaris updates are going to start coming more slowly, because new patches are causing new problems and QA testers can’t keep up

ThePawn.com June 19, 2025
World of Warcraft dataminers dug up its biggest boss ever: A new 3,806-foot-tall horror who could crush its capital cities in one step
2 min read
  • News

World of Warcraft dataminers dug up its biggest boss ever: A new 3,806-foot-tall horror who could crush its capital cities in one step

ThePawn.com June 19, 2025

Latest YouTube Video

Check out these awesome streamers

ThePawn02 on twitch

From Gamewatcher

  • Tempest Rising's First Major Content Update, Rally & Recon, Adds Six New Maps, 2v2 Ranked, Spectator Mode, and More
  • Roguelike 2D Action-Platformer Autogun Heroes: Supercharged Blasts Its Way to PC
  • Chrono Odyssey Preview
  • Warhammer 40,000: Space Marine Review
  • Dune: Awakening Review

From IGN

  • Deals for Today: Nintendo Switch Power Bank, Death Stranding Vinyl, Skytech Gaming PC, and More
  • Nintendo Confirms Pauline's Age in Donkey Kong Bananza — Leaving Fans Wondering Whether It's a Super Mario Odyssey Prequel, and If Mario Will Appear As a Potential Villain
  • Elden Ring Nightreign Latest Patch Shadowdropped Its First Enhanced Boss
  • Donkey Kong Bananza Is Getting an Amiibo, and It's Now Available To Preorder
  • Beat Saber Ends Support on PS4 and PS5 in Yet Another Blow for PSVR2

From Kotaku

  • At Least One Band Is Bummed To Be Cut From THPS 3+4
  • The Nintendo Console Launches, Ranked From Worst To Best
  • Stellar Blade, As Told By Steam Reviews
  • Tips For Playing The Magic: the Gathering x Final Fantasy VII Commander Deck
  • 10 Shark Movies to Sink Your Teeth Into (That Aren’t Jaws)

.

You may have missed

Wordle hint and answer today #1462 (June 20 2025)
1 min read
  • Guides

Wordle hint and answer today #1462 (June 20 2025)

ThePawn.com June 19, 2025
NYT Connections hint (Fri, 20 Jun)
1 min read
  • Guides

NYT Connections hint (Fri, 20 Jun)

ThePawn.com June 19, 2025
Rematch launched without crossplay because of ‘unforeseen technical complexities’ and Sloclap is sorry, but it’s a hit on Steam anyway
3 min read
  • News

Rematch launched without crossplay because of ‘unforeseen technical complexities’ and Sloclap is sorry, but it’s a hit on Steam anyway

ThePawn.com June 19, 2025
Stellaris updates are going to start coming more slowly, because new patches are causing new problems and QA testers can’t keep up
2 min read
  • News

Stellaris updates are going to start coming more slowly, because new patches are causing new problems and QA testers can’t keep up

ThePawn.com June 19, 2025
Privacy Policy
  • Home
  • Watch Live
  • News
  • eSports
  • Blog
  • Reviews
  • Guides
  • Guild Login
  • Socials
  • Twitch
  • YouTube
  • Instagram
  • Twitter
  • Facebook
  • Kick.com
Copyright © All rights reserved. | MoreNews by AF themes.