AMD EPYC 7001
cpe:2.3:h:amd:epyc_7001:*:*:*:*:*:*:*, +11 more
A transient execution vulnerability has been identified in multiple generations of AMD CPUs. This vulnerability may allow a local user-privileged attacker to leak sensitive data through the floating-point divisor unit, potentially leading to a loss of confidentiality. The issue affects systems with Simultaneous Multithreading (SMT) enabled, as well as those without it.
Exploitation of this vulnerability could result in unauthorized data leakage, compromising sensitive information.
For affected Zen and Zen+ processors, this vulnerability may be mitigated at the operating system level by setting bit 9 of MSR C001_1028 to 1. AMD is collaborating with upstream Linux maintainers to facilitate the integration of this mitigation. Users are advised to contact their operating system vendor regarding available mitigations.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.