Friday, May 3rd 2024

AMD Patches Zenbleed Vulnerability with AGESA 1.2.0.Ca Update

AMD classified the Zenbleed vulnerability, CVE-2023-20593, as a medium-level threat about a year ago. AMD has acknowledged that it could potentially allow an attacker to access sensitive information under certain microarchitectural circumstances. Today, MSI has released new BIOS updates featuring AMD's AM4 AGESA 1.2.0.Ca firmware update. This update addresses the Zenbleed vulnerability affecting AMD's Ryzen 4000 series Zen 2 APUs. MSI is proactively rolling out the new BIOS updates across its range of compatible motherboards. The updates are currently available for almost all X570 motherboards, with support for other chipsets and 400 series motherboards expected to follow soon.

The AGESA 1.2.0.Ca firmware update specifically targets the Zenbleed vulnerability in the Zen 2 microarchitecture. Although the vulnerability primarily affects Ryzen 4000 "Renoir" APUs, it also exists in other Zen 2 processors, including the Ryzen 3000 series and certain EPYC and Threadripper CPUs. AMD has already addressed the Zenbleed vulnerability in previous AGESA microcode updates for Ryzen 3000 processors and other platforms, such as EPYC server CPUs and Ryzen mobile CPUs. However, the Ryzen Embedded V2000 CPUs are still awaiting the EmbeddedPi-FP6 1.0.0.9 AGESA firmware update, which is expected to be released by April. While AMD has not explicitly stated whether the security update will impact performance, previous testing of Zenbleed fixes has shown potential performance drops of up to 15% in certain workloads, although gaming performance remained relatively unaffected. Users with AM4 chips based on architectures other than Zen 2, such as Zen+ or Zen 3, do not need to update their BIOS as they are not affected by this specific vulnerability.
Source: Tom's Hardware
Add your own comment

30 Comments on AMD Patches Zenbleed Vulnerability with AGESA 1.2.0.Ca Update

#26
RJARRRPCGP
Waldorf@RJARRRPCGP
definitely something up if used on 5000 series, event log full of critical issue,
only starting after 1.2.c, and none since i downgraded back to 1.2.b.
I don't have that issue on my Asus ROG Strix B550-F Gaming. Did you check to see if it's because of Windows not shutting down properly? It could very well be hybrid-sleep striking again!
Posted on Reply
#27
Waldorf
anything like it is turned off, as well as some of the errors not related to that.
and as i have gpu lights, i know if its really off.
ahh, not really an issue, as nothing fixed for "me", so staying on b..
Posted on Reply
#28
mechtech
Waldorfummm, but it says 1.2.B?
thats the (old) "latest" for those not affected, 1.2.C is the security fix for pre 5000 series,
unless you're using d-sub (included fix), no need to install C on yours.
Ya not enough words........meant another newer one as I had just updated to a "new" one 2 weeks ago.

See how long it takes gigabyte to update the site/FW.
Posted on Reply
#29
Waldorf
@Makaveli
different board/maker/cpu, lots of things can be the cause,

worked prior, shortly after install i get errors, after going back to b its now fine for 5 days of use,
no changes on win, no updates etc, no AMP/oc, identical settings for everything else, so..
just saying, its not fine on mine, might even be only MSI/my board having wrong (bios) values on something.

then again, isnt for 5 series, so might just be that..
Posted on Reply
#30
mechtech
Asus Pro B550M-C CSM had this out awhile ago!!

Posted on Reply
Add your own comment
Jun 1st, 2024 21:18 EDT change timezone

New Forum Posts

Popular Reviews

Controversial News Posts