bIGmAC 📶 · @dk3jf
271 followers · 1882 posts · Server radiosocial.de

#zenbleed

Last updated 1 year ago

DarkCyberMan · @darkcyberman
23 followers · 277 posts · Server nerdculture.de

Can’t find any statement from Microsoft regarding Azure and (CVE-2023-20593) mitigation. At least Aws and google published statements for their clouds.

#zenbleed

Last updated 1 year ago

Melroy van den Berg · @melroy
77 followers · 511 posts · Server mastodon.melroy.org

When looking at all the CPU vulnerabilities in the recent years even until this day. We see mitigations taking place in microcode or OS level. But the performance impact is huge! Sometimes 30%-50% decrease in performance on specific tasks like databases!
Question: can we get some compensation as consumer? Since both Intel and AMD sold hardware that doesn't give the promised results.

#specre #meltdown #hertzbleed #zenbleed #inception #vulnerability #security #secops #compensation #money

Last updated 1 year ago

The kernel wants, for my CPU (Ryzen 3600), microcode revision 0x8701032. The latest available (only via BIOS updates, not linux-firmware) is 0x8701030, and the kernel complains about it:

“Zenbleed: please update your microcode for the most optimal fix”

#linux #amd #ryzen #zenbleed

Last updated 1 year ago

Andrei G. :unverified: · @ndrei
57 followers · 415 posts · Server fosstodon.org

added fix for .

You'll ask yourself: what, wasn't this fixed last month? Yes, it was but not for the Steam Deck APU - the CPU model was missed in the Zenbleed erratum list. The fix is going to hit v6.5-rc6.

phoronix.com/news/Linux-Zenble

#linux #zenbleed #SteamDeck

Last updated 1 year ago

ricardo :mastodon: · @governa
1347 followers · 8751 posts · Server fosstodon.org

Kernel Updated To Add Fix For Valve's :steamdeck:

phoronix.com/news/Linux-Zenble

#linux #zenbleed #SteamDeck

Last updated 1 year ago

Thomas Hurst · @Freaky
172 followers · 435 posts · Server hachyderm.io

I added a known-good microcode check to my MSR chicken-bit rc script, and a reminder to check it all again in mid-December.

I don't have the relevant CPUs to hand to test it directly so do let me know how you get on.

gist.github.com/Freaky/2560975

#freebsd #zenbleed

Last updated 1 year ago

FelixCLC (still waiting on HR) · @fclc
489 followers · 1768 posts · Server mast.hpc.social

@Violet This years looks ripe with CPU vulnerabilities.

last week for AMD

today:
for Intel

for AMD

#defcon #zenbleed #downfall #inception

Last updated 1 year ago

Ubuntu Security · @ubuntusecurity
539 followers · 38 posts · Server fosstodon.org

On the @ubuntu Podcast this week we look at the AMD vuln plus we cover security updates for the Linux kernel, a high profile OpenSSH vuln and finally Andrei is back covering recent academic research in machine learning safeguards ubuntusecuritypodcast.org/epis

#security #zenbleed

Last updated 1 year ago

The Register · @theregister
2700 followers · 8908 posts · Server geeknews.chat

Unfortunately @theregister published misleading and incorrect information that using QEMU (i.e. KVM / Firecracker) mitigates the AMD exploit.

_It does not_

We demo the exploit in a GitHub Action and show how to mitigate it.
actuated.dev/blog/amd-zenbleed


Original tweet : nitter.it/alexellisuk/status/1

#bot #zenbleed

Last updated 1 year ago

Hopbox by Unmukti · @Hopbox
4 followers · 3 posts · Server mastodon.hopbox.net

FIxes for AMD 'Zenbleed' CVE-2023-20593 has landed in Debian archives. For stable (bookworm), vulnerability is fixed in Linux version 6.1.38-2 and for old-stable (bullseye) fix is in version 5.10.179-3.

This only fixes for 2nd gen Epyc CPUs, further CPUs to follow in later releases. Please update your Debian (and downstream) servers.

#debian #zenbleed #hopbox

Last updated 1 year ago

PrivacyDigest · @PrivacyDigest
506 followers · 1875 posts · Server mas.to

'Zenbleed' Bug Leaks Data From Zen 2 , CPUs: Most Patches Coming Q4 (Updated) | Tom's Hardware

tomshardware.com/news/zenbleed

#privacy #zenbleed #epyc #ryzen #amd

Last updated 1 year ago

Stefano Marinelli · @stefano
573 followers · 437 posts · Server mastodon.bsd.cafe
ITSEC News · @itsecbot
1402 followers · 36320 posts · Server schleuss.online
JmpLemur · @jmplemur
0 followers · 4 posts · Server fosstodon.org

How painful is actually going to be to AMD customers? Personally I hope it amounts to nothing. Same with similar Intel bugs. Most of these things are really difficult to fix without trade-offs and they were somewhere difficult to see coming until like 8 or so years ago

#zenbleed

Last updated 1 year ago

Mr.Trunk · @mrtrunk
5 followers · 8027 posts · Server dromedary.seedoubleyou.me
Ed W8EMV · @w8emv
364 followers · 611 posts · Server hachyderm.io

@lengau

there was a embargo with a release date in early August, info got released early, hence the scramble by some; enterprises have a harder time scrambling.

#zenbleed

Last updated 1 year ago

Noxy 🐾 · @noxypaws
276 followers · 4025 posts · Server packmates.org

also me reading the blog post:

(art by the outstanding feral artist Paper-Wings)

#zenbleed

Last updated 1 year ago

Noxy 🐾 · @noxypaws
276 followers · 4025 posts · Server packmates.org

Me reading the blog post:

#zenbleed

Last updated 1 year ago

Ed W8EMV · @w8emv
364 followers · 611 posts · Server hachyderm.io

Puzzled for the moment that the public Red Hat bug tracking is priority "medium", assignee "nobody"

bugzilla.redhat.com/show_bug.c

and that the CVE they rate as "moderate impact"

access.redhat.com/security/cve

[ ]

#zenbleed #cve #rhel #redhat

Last updated 1 year ago