JUL 15 · 2024·1 min read
Reading microcode patches off Zen2 via the PMU over SMBus
The PMU's branch-misprediction counter leaks one bit of microcode per measurement on Zen2. 512 measurements yield a full patch word. The attack is unprivileged and works inside a VM.
High 8.1PATCHED
Full writeup coming soon.