CVE-2020-12965

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
04/02/2022
Last modified:
06/12/2023

Description

When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:amd:ryzen_pro_5650g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_pro_5650g:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_pro_5650ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_pro_5650ge:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_pro_5750g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_pro_5750g:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_pro_5750ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_pro_5750ge:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_pro_5350g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_pro_5350g:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_pro_5350ge_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_pro_5350ge:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_pro_4750g_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:amd:ryzen_pro_4750g:-:*:*:*:*:*:*:*
cpe:2.3:o:amd:ryzen_pro_4750ge_firmware:-:*:*:*:*:*:*:*