Update 7/24/23 5:40pm PT: Added a statement from Google and also a full list of all impacted processors and the expected dates for patches for each model.
Update 7/24/23 1:30pm PT:
Original Article Published 7/24/23 8:45am PT:
This works because the register file is shared by everything on the same physical core. In fact, two hyperthreads even share the same physical register file," says Ormandy.
Swipe to scroll horizontally
| Processor | Agesa Firmware | Availability to OEMs | Microcode |
| 2nd-Gen AMD EPYC Rome Processors | RomePI 1.0.0.H | Now | 0x0830107A |
| Ryzen 3000 Series “Matisse” | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Target Dec 2023 for both | ? |
| Ryzen 4000 Series "Renoir" AM4 | ComboAM4v2PI_1.2.0.C | Target Dec 2023 | ? |
| Threadripper 3000-Series "Caslle Peak" | CastlePeakPI-SP3r3 1.0.0.A | Target Oct 2023 | ? |
| Threadripper PRO 3000WX-Series "Castle Peak" | CastlePeakWSPI-sWRX8 1.0.0.C | ChagallWSPI-sWRX8 1.0.0.7 | Target Nov 2023 | Target Dec 2023 | ? |
| Ryzen 5000 Series Mobile "Lucienne" | CezannePI-FP6_1.0.1.0 | Target Dec 2023 | ? |
| Ryzen 4000 Series Mobile "Renoir" | RenoirPI-FP6_1.0.0.D | Target Nov 2023 | ? |
| Ryzen 7020 Series "Mendocino" | MendocinoPI-FT6_1.0.0.6 | Target Dec 2023 | ? |
Below, we have a more detailed list with the model number of each impacted chip and the expected data for the new AGESA to arrive. AMD's AGESA is a code foundation upon which the OEMs build BIOS revisions. You will need to update to a BIOS with the above-listed AGESA code, or newer, to patch your system.
“We are aware of the AMD hardware security vulnerability described in CVE-2023-20593, which was discovered by Tavis Ormandy, a Security Researcher at Google, and we have worked with AMD and industry partners closely. We have worked to address the vulnerability across Google platforms.” - Google spokesperson to Tom's Hardware.Ormandy says he reported the issue to AMD on May 15, 2023. Ormandy also credits his colleagues; "I couldn’t have found it without help from my colleagues, in particular Eduardo Vela Nava and Alexandra Sandulescu. I also had help analyzing the bug from Josh Eads."
Swipe to scroll horizontally
| Desktop CPU | New Agesa Firmware Version | Patch Due |
|---|---|---|
| Ryzen 3 3100 | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 3 3300X | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 3 4100 | ComboAM4v2PI_1.2.0.C | Nov 2023 |
| Ryzen 3 4300G | ComboAM4v2PI_1.2.0.C | Dec 2023 |
| Ryzen 3 4300GE | ComboAM4v2PI_1.2.0.C | Dec 2023 |
| Ryzen 4700S | ComboAM4v2PI_1.2.0.C | Nov 2023 |
| Ryzen 5 3500 | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 5 3500X | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 5 3600 | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 5 3600X | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 5 3600XT | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 5 4500 | ComboAM4v2PI_1.2.0.C | Nov 2023 |
| Ryzen 5 4600G | ComboAM4v2PI_1.2.0.C | Dec 2023 |
| Ryzen 5 4600GE | ComboAM4v2PI_1.2.0.C | Dec 2023 |
| Ryzen 7 3700X | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 7 3800X | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 7 3800XT | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 7 4700G | ComboAM4v2PI_1.2.0.C | Dec 2023 |
| Ryzen 7 4700GE | ComboAM4v2PI_1.2.0.C | Dec 2023 |
| Ryzen 9 3900 | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 9 3900X | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 9 3900XT | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen 9 3950X | ComboAM4v2PI_1.2.0.C | ComboAM4PI_1.0.0.C | Dec 2023 |
| Ryzen Threadripper 3960X | CastlePeakWSPI-sWRX8 1.0.0.C | ChagallWSPI-sWRX8 1.0.0.9 | Nov 2023 / Dec 2023 |
| Ryzen Threadripper 3970X | CastlePeakWSPI-sWRX8 1.0.0.C | ChagallWSPI-sWRX8 1.0.0.8 | Nov 2023 / Dec 2023 |
| Ryzen Threadripper 3990X | CastlePeakWSPI-sWRX8 1.0.0.C | ChagallWSPI-sWRX8 1.0.0.7 | Nov 2023 / Dec 2023 |
| Ryzen Threadripper Pro 3945WX | CastlePeakWSPI-sWRX8 1.0.0.C | ChagallWSPI-sWRX8 1.0.0.13 | Nov 2023 / Dec 2023 |
| Ryzen Threadripper Pro 3955WX | CastlePeakWSPI-sWRX8 1.0.0.C | ChagallWSPI-sWRX8 1.0.0.12 | Nov 2023 / Dec 2023 |
| Ryzen Threadripper Pro 3975WX | CastlePeakWSPI-sWRX8 1.0.0.C | ChagallWSPI-sWRX8 1.0.0.10 | Nov 2023 / Dec 2023 |
| Ryzen Threadripper Pro 3995WX | CastlePeakWSPI-sWRX8 1.0.0.C | ChagallWSPI-sWRX8 1.0.0.11 | Nov 2023 / Dec 2023 |
Swipe to scroll horizontally
| Mobile CPU | New Agesa Firmware Version | Patch Due |
|---|---|---|
| Ryzen 3 4300U | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 3 5300U | CezannePI-FP6_1.0.1.0 | Dec 2023 |
| Ryzen 3 7320U | MendocinoPI-FT6_1.0.0.6 | Dec 2023 |
| Ryzen 5 4500U | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 5 4600H | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 5 4600HS | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 5 4600U | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 5 4680U | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 5 5500U | CezannePI-FP6_1.0.1.0 | Dec 2023 |
| Ryzen 5 7520U | MendocinoPI-FT6_1.0.0.6 | Dec 2023 |
| Ryzen 7 4700U | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 7 4800U | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 7 4980U | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 7 5700U | CezannePI-FP6_1.0.1.0 | Dec 2023 |
| Ryzen 9 4900H | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 9 4800H | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 9 4800HS | RenoirPI-FP6_1.0.0.D | Nov 2023 |
| Ryzen 9 4900HS | RenoirPI-FP6_1.0.0.D | Nov 2023 |
Swipe to scroll horizontally
| Server CPU | New Agesa Firmware Version | Patch Available |
|---|---|---|
| EPYC 7232P | RomePI 1.0.0.H | Now |
| EPYC 7252 | RomePI 1.0.0.H | Now |
| EPYC 7262 | RomePI 1.0.0.H | Now |
| EPYC 7272 | RomePI 1.0.0.H | Now |
| EPYC 7282 | RomePI 1.0.0.H | Now |
| EPYC 7302 | RomePI 1.0.0.H | Now |
| EPYC 7302P | RomePI 1.0.0.H | Now |
| EPYC 7352 | RomePI 1.0.0.H | Now |
| EPYC 7402 | RomePI 1.0.0.H | Now |
| EPYC 7402P | RomePI 1.0.0.H | Now |
| EPYC 7452 | RomePI 1.0.0.H | Now |
| EPYC 7502 | RomePI 1.0.0.H | Now |
| EPYC 7502P | RomePI 1.0.0.H | Now |
| EPYC 7532 | RomePI 1.0.0.H | Now |
| EPYC 7542 | RomePI 1.0.0.H | Now |
| EPYC 7552 | RomePI 1.0.0.H | Now |
| EPYC 7642 | RomePI 1.0.0.H | Now |
| EPYC 7662 | RomePI 1.0.0.H | Now |
| EPYC 7702 | RomePI 1.0.0.H | Now |
| EPYC 7702P | RomePI 1.0.0.H | Now |
| EPYC 7742 | RomePI 1.0.0.H | Now |
| EPYC 7F32 | RomePI 1.0.0.H | Now |
| EPYC 7F52 | RomePI 1.0.0.H | Now |
| EPYC 7F72 | RomePI 1.0.0.H | Now |
| EPYC 7H12 | RomePI 1.0.0.H | Now |