AMD Zenbleed Vulnerability Fix Tested: Some Apps Drop 15%, Gaming Unaffected

Ryzen die
(Image credit: Fritchenz Fritz)

A Google security researcher recently unveiled the startling new Zenbleed vulnerability that lays bare the most sensitive information passing through AMD's Zen 2 processors, like encryption keys and user logins, thus allowing an attacker to steal data and compromise a system entirely. We learned about a workaround that can patch the issue, and even though the fix doesn't persist through reboots, it allowed us to run a series of tests to determine the performance impact of enabling a patch, which AMD will be releasing in the near future. 

Our testing revealed that some workloads, like encoders and renderers, can suffer performance losses of up to ~15%, while other types of desktop PC applications are either unimpacted or can even experience a slight uptick in performance after the patches. Those focused solely on gaming can breathe a sigh of relief, though, as our tests didn't reveal any significant performance penalties in several titles.

Paul Alcorn
Editor-in-Chief

Paul Alcorn is the Editor-in-Chief for Tom's Hardware US. He also writes news and reviews on CPUs, storage, and enterprise hardware.

  • Makaveli
    "The Zenbleed flaw (CVE-2023-20593) spans the entire Zen 2 product stack, including AMD's EPYC data center processors and Ryzen 3000/4000/5000 CPUs"

    Just to make it more clear this is Zen 2 5000 chips not Zen 3
    Reply
  • Roland Of Gilead
    Makaveli said:
    "The Zenbleed flaw (CVE-2023-20593) spans the entire Zen 2 product stack, including AMD's EPYC data center processors and Ryzen 3000/4000/5000 CPUs"

    Just to make it more clear this is Zen 2 5000 chips not Zen 3
    Yup! Only the U series 5000, which aren't Zen 3. Good spot!
    Reply
  • ezst036
    Where can I go to see what vulnerabilities are fixed in hardware? - so they do not require these costly software fixes anymore? Is there any website out there which lists these vulnerabilities, perhaps in a table format?
    Reply
  • drajitsh
    Thanks for covering security so well. This along with guides is the main thing keeping me checking the site on a daily basis.
    Reply
  • dmitche3
    My question is, since I really don't care to make this patch on my AMD systerm, how can I avoid having this patched? Will it be a Microsoft behidn the scenes or a MOBO mfg update?
    Reply
  • ghedepere
    This smells kind of fake, or blown out of proportion like intel and AMD both had fake vulnerabities spun up after spectre and meltdown to affect share price and manipulate the stock market.

    This is even more suspect when people urge you to update, even if you are not affected.
    This updating for the sake of updating, not reading release notes and just accepting things blindly has to stop, it's paving the way for some very cheap planned software obsolescence through performance reductions and functionality removals.

    Curious to see the answers to others' questions about where to find info in a table for all vulnerabilities that are being patches through microcode and their impact, as well as how to tell the OS is going to push for a microcode update or not.
    Reply
  • JakeTheMate
    dmitche3 said:
    My question is, since I really don't care to make this patch on my AMD systerm, how can I avoid having this patched? Will it be a Microsoft behidn the scenes or a MOBO mfg update?
    Microsoft patched this on last "Patch Tuesday", so anybody with an up to date Win10/11 system should no longer vulnerable. Don't know if that helps with avoiding the patch.
    Reply