A flaw was found in hw. Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions.
A flaw was found in HW. When SMT is enabled, certain AMD processors may speculatively execute instructions using a target from the sibling thread after an SMT mode switch potentially resulting in information disclosure.
References: https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1045 https://www.openwall.com/lists/oss-security/2023/02/14/4 https://xenbits.xen.org/xsa/advisory-426.html https://kernel.org/doc/html//next/admin-guide/hw-vuln/cross-thread-rsb.html
AMD Ryzen, Gen AMD EPYC Processors could allow a local authenticated attacker to obtain sensitive information, caused by a use-after-free flaw in the vzeroupper instruction. By conducting a cache timing attack using a specially crafted application, an attacker could exploit this vulnerability to obtain sensitive data used by other processes, such as passwords and encryption keys, at a rate of 30KB/sec from each CPU core.
A flaw was found in hw. Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type, potentially leading to information disclosure.
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
Improper initialization of variables in the DXE driver may allow a privileged user to leak sensitive information via local access.
A flaw was found in hw. This issue can cause AMD CPUs to transiently execute beyond unconditional direct branches.