Vulnerability CVE-2017-7262


Published: 2017-03-24   Modified: 2017-03-25

Description:
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.

CVSS2 => (AV:L/AC:L/Au:N/C:N/I:N/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4.9/10
6.9/10
3.9/10
Exploit range
Attack complexity
Authentication
Local
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
None
Complete
Affected software
AMD -> Ryzen 

 References:
http://forum.hwbot.org/showpost.php?p=480524
http://forum.hwbot.org/showthread.php?t=167605
http://www.securityfocus.com/bid/97098
https://news.ycombinator.com/item?id=13924192
https://www.techpowerup.com/231536/amd-ryzen-machine-crashes-to-a-sequence-of-fma3-instructions

Copyright 2024, cxsecurity.com

 

Back to Top