Database/Control plane, storage & DevOps
AMD Zen 3 / Zen 4 - new exploitation method for SRSO (CVE-2023-20569): Google's security team demonstrated a new way to
Impact
Google's security team demonstrated a new way to exploit the existing Inception/SRSO defect on Zen 3 and Zen 4. No new CVE was assigned and AMD asserts the original mitigations still hold. Recorded here because it is the kind of update that never reaches a patch queue: nothing to install, but your risk assessment of an already-known issue should move if the exploitation bar just dropped.
Who can reach it
Local, cross-privilege speculative execution on Zen 3 and Zen 4.
What to do
**No new action** if you already applied the original SRSO mitigations (microcode plus AGESA, MilanPI 1.0.0.C / GenoaPI 1.0.0.9 or later, plus the kernel's Safe RET). Verify that you did - read /sys/devices/system/cpu/vulnerabilities/spec_rstack_overflow across the fleet rather than assuming. Note the interaction with AMD-SB-7061 above: Safe RET, the mitigation you are relying on here, has its own open weakness.
References
Related entries
- AMD confidential computing - DDR5 memory bus interposition against TEEs: Compromising trusted execution environments byNCVD-2025-006-amd-confidential-computing-ddr5 · AMD confidential computing - DDR5 memory bus interposition against TEEsUnscored
- DMTF libspdm (GET_MEASUREMENT_EXTENSION_LOG offset/length wrap): Wrapping addition of the Offset and Length fieldsNCVD-2026-001-dmtf-libspdm-get-measurement-ext · DMTF libspdm (GET_MEASUREMENT_EXTENSION_LOG offset/length wrap)Unscored
- Linux Safe RET SRSO mitigation on AMD Zen 1-Zen 4 - interrupt-induced weakening: An attacker executing code on theNCVD-2026-001-linux-safe-ret-srso-mitigation-o · Linux Safe RET SRSO mitigation on AMD Zen 1-Zen 4 - interrupt-induced weakeningUnscored
- DMTF libspdm (cryptlib_mbedtls CSR generation, stack overflow): An over-long Common Name in a GET_CSR request writesNCVD-2026-002-dmtf-libspdm-cryptlib-mbedtls-cs · DMTF libspdm (cryptlib_mbedtls CSR generation, stack overflow)Unscored
- AMD - REP-string execution unit scheduler contention side channel: A newer variant of the SQUIP scheduler-contentionNCVD-2026-003-amd-rep-string-execution-unit-sc · AMD - REP-string execution unit scheduler contention side channelUnscored
- Das U-Boot (FIT image signature verification): Binarly disclosed a cluster of flaws in U-Boot's FIT image handlingNCVD-2026-005-das-u-boot-fit-image-signature-v · Das U-Boot (FIT image signature verification)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.