Database/Kernel, userspace & hypervisor
AMD CPU (Zenbleed): Zenbleed: cross-process/cross-VM register-file data leak on Zen 2 at ~30 kB/s per core, no special
Impact
Zenbleed: cross-process/cross-VM register-file data leak on Zen 2 at ~30 kB/s per core, no special privileges
Who can reach it
Any tenant process in a container; tenant VM guest
What to do
AMD microcode (AGESA) update + reboot; kernel chicken-bit workaround (DE_CFG[9]) available with a measured perf cost. Zen 2 EPYC is still common as the CPU side of A100/L40S nodes
Fleet impact
How widespread
common - Zen 2 EPYC (Rome) still hosts a large installed base of GPU nodes and rental fleets
Cost to remediate
microcode+reboot for the real fix; the interim DE_CFG MSR chicken-bit workaround is a kernel change with a measurable FP/vector performance cost - so the fleet either reboots for microcode or eats a permanent tax
Why it hits the whole fleet
Leaks ~30 KB/s/core of stale vector-register data across any privilege boundary including cross-process and cross-VM, i.e. exactly the co-tenancy isolation a GPU cloud sells, on every Rome host at once.
References
Related entries
- GPU local/shared memory not cleared between kernels (AMD, Apple, Qualcomm, Imagination): A GPU kernel reads whateverCVE-2023-4969 · GPU local/shared memory not cleared between kernels (AMD, Apple, Qualcomm, Imagination)Medium
- Linux kernel (net/xfrm): XFRM_MSG_NEWAE lets a caller update replay-window state on a state that never had replay_esnCVE-2023-53147 · Linux kernel (net/xfrm)Medium
- Linux kernel (drivers/vfio): Pinned-memory accounting for a VFIO container is lost across exec(), then underflows to aCVE-2023-53171 · Linux kernel (drivers/vfio)Medium
- Linux kernel (drivers/iommu/iommufd): Iommufd accepts a user address plus length that wraps past zero, then asks the mmCVE-2023-54239 · Linux kernel (drivers/iommu/iommufd)Medium
- Oracle VirtualBox: Easily exploitable Core flaw allowing unauthorised access to VirtualBox-accessible dataCVE-2024-21121 · Oracle VirtualBoxMedium
- Intel ice driver (Ethernet 800 Series, Linux kernel mode): A protection-mechanism failure in the E810 Linux kernelCVE-2024-23499 · Intel ice driver (Ethernet 800 Series, Linux kernel mode)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.