AMD 'Inception' Vulnerability Affects Zen 3 and 4

AMD Ryzen 'Inception' attack
(Image credit: COMSEC)

Swiss researchers have found holes in AMD Ryzen processor security. AMD has outlined the newly uncovered "Inception" attack in its official CVE-2023-20569 bulletin. Like some of the most infamous CPU vulnerabilities, Inception is a speculative side channel attack, which can possibly lead to privileged data leakage to unprivileged processes. At the time of writing AMD is not aware of any Inception exploits outside of security research circles.

Unfortunately for AMD and its users, Inception affects the latest AMD Ryzen processor families based on Zen 3 and Zen 4 cores — across data center, desktop, HEDT, and mobile. However, we must be thankful that, as details of Inception go live, mitigations are in the pipeline.

Latest Videos FromTom's Hardware
Mark Tyson
News Editor

Mark Tyson is a news editor at Tom's Hardware. He enjoys covering the full breadth of PC tech; from business and semiconductor design to products approaching the edge of reason.

  • bit_user
    Microcode updates for Linux have already been merged. The performance impact of the mitigation is said to be minor. I'll be interested in seeing some benchmarks.

    I've seen this described as just a special case of the SRSO (Speculative Return Stack Overflow) exploits we already knew about.
    Reply
  • wbfox
    At least AMD got the microcode updates out for everyone already. They did the updgrade shaft dance to the Zen 2 owners with their, "maybe next year," Zenbleed fix.
    Reply
  • Integr8d
    The timing of this article and the Intel article are... hmmm.

    To say the least, it feels coordinated. Anyone's guess as to why.
    Reply
  • BernardTitus
    Integr8d said:
    The timing of this article and the Intel article are... hmmm.

    To say the least, it feels coordinated. Anyone's guess as to why.
    Black Hat and Def Con are happening now.
    Reply
  • Alvar "Miles" Udell
    To be clear, AMD says that users of products based on the Zen or Zen 2 CPU architectures don't need any patching "because these architectures are already designed to flush branch type predictions from the branch predictor." This is a little different from what the researchers from ETH Zurich say in their Inception paper (PDF), so we hope things will become clearer soon.

    So AMD took a step backwards in security to take a step forward in performance it sounds like.
    Reply