Encryption-breaking, password-leaking bug in many AMD CPUs could take months to fix

Lanky_Pomegranate530@lemmy.world to Technology@lemmy.world – 589 points –
Encryption-breaking, password-leaking bug in many AMD CPUs could take months to fix
arstechnica.com
96

You are viewing a single comment

Planned fix

December 2023

Yikes.

It's worth noting these are the firmware / microcode fixes.

There's already a software solution available,

There is a software workaround, you can set the chicken bit DE_CFG[9]. This may have some performance cost, and the microcode update is preferred.

source: https://www.openwall.com/lists/oss-security/2023/07/24/3

AMD has also already released a fix for the big boy - the EPYC processor.

The MSR bit is potentially a large performance loss and AMD recommends their partners not use it. In my tests is was 5-15% on EPYC depending on workload. "Some performance cost" is really hiding the reality of that bit.