First published: Sat Mar 25 2017(Updated: )
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
AMD CPUs | <=2017-01-27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-7262 is classified as a denial of service vulnerability.
To mitigate CVE-2017-7262, update the AGESA microcode for AMD Ryzen processors to a version released after January 27, 2017.
Local users of AMD Ryzen processors with AGESA microcode version up to and including January 27, 2017 are affected by CVE-2017-7262.
CVE-2017-7262 enables a denial of service attack by causing system hangs through excessive FMA3 instructions.
CVE-2017-7262 cannot be exploited remotely as it requires local user access to the affected system.