JUL 15 · 2024·1 min read

Reading microcode patches off Zen2 via the PMU over SMBus

The PMU's branch-misprediction counter leaks one bit of microcode per measurement on Zen2. 512 measurements yield a full patch word. The attack is unprivileged and works inside a VM.

High 8.1PATCHED

Full writeup coming soon.