Red Hat released kernel and linux-firmware updates across supported RHEL 7, 8, and 9 streams to address two AMD processor side-channel flaws: CVE-2023-20593 (Zenbleed) and CVE-2023-20569 (Inception/RAS Poisoning). Zenbleed affects AMD Zen 2 processors and may expose data left in YMM registers by another process or thread; Inception can let a local attacker manipulate return-address prediction and induce speculative execution that discloses information. Both issues require local, low-privilege access and primarily affect confidentiality.
The remediation includes AMD microcode delivered through updated linux-firmware packages and, for applicable RHEL streams, kernel updates. Red Hat issued linux-firmware-20200421-81.git78c0348.el7_9 for RHEL 7 and linux-firmware-20180911-69.2.git85c5d90.el7_6 for RHEL Server AUS 7.6; RHEL 9.0 EUS kernel 5.14.0-70.80.1.el9_0 also includes fixes for the AMD flaws alongside other kernel vulnerabilities. Administrators should apply the relevant supported-channel updates and reboot systems after kernel installation so protections take effect.

See real exploitation activity before you spend the cycle.
17 events from the most recent confirmed update back to the earliest known activity.
Red Hat issued Moderate advisory RHSA-2023:7513, updating RHEL 7 linux-firmware to version linux-firmware-20200421-81.git78c0348.el7_9 and remediating CVE-2023-20569 and CVE-2023-20593.
Red Hat issued Moderate advisory RHSA-2023:7401, updating RHEL 8.6 extended-support linux-firmware packages to remediate CVE-2023-20569 (Inception) and CVE-2023-20593 (Zenbleed). The update covered EUS, AUS, TUS, SAP, and other RHEL 8.6 offerings across x86_64, s390x, ppc64le, and aarch64.
Red Hat issued Important advisory RHSA-2023:7382 for RHEL 9.0 Extended Update Support, supplying kernel 5.14.0-70.80.1.el9_0 and fixes for seven CVEs, including CVE-2023-20593. Systems require a reboot after installation for the new kernel fixes to take effect.
RHSA-2023:7244 fixed CVE-2023-20569 and CVE-2023-20593 in RHEL 7.7 Advanced Update Support linux-firmware packages.
Red Hat issued RHSA-2023:7109 to address CVE-2023-20569 in the RHEL 8 linux-firmware package.
RHSA-2023:4819 and RHSA-2023:4821 remediated CVE-2023-20593 in the standard RHEL 7 kernel and kernel-rt packages.
Red Hat issued RHSA-2023:4699 and RHSA-2023:4696, providing kernel fixes for CVE-2023-20593 (Zenbleed) in the RHEL 7.4 and 7.6 Advanced Update Support streams.
Red Hat publicly listed CVE-2023-20569, an AMD return-address-prediction side-channel flaw that may enable information disclosure through attacker-influenced speculative execution.
Red Hat issued RHBA-2023:2977 for RHEL 8 linux-firmware, which Red Hat later identified as addressing CVE-2023-20569 (Inception/RAS Poisoning).
Red Hat remediated CVE-2023-20593 through further kernel and linux-firmware advisories for RHEL 7, 8, and 9, including extended and specialized support streams through RHSA-2024:0402, RHSA-2024:0403, and RHSA-2024:0561.
Red Hat issued further CVE-2023-20569 fixes for RHEL 9.0 and 9.2 Extended Update Support, RHEL 8.4 mission-critical, SAP, and telecommunications channels, RHEL 8.6 EUS, and RHEL 8.8 EUS through advisories including RHSA-2024:0433, RHSA-2024:0439, RHSA-2024:0448, RHSA-2024:0449, RHSA-2024:0561, RHSA-2024:0724, and RHSA-2024:5255.
Red Hat added CVE-2023-20569 to the Red Hat Bug Fix Advisory RHBA-2023:2977.
Red Hat issued RHSA-2024:2005 to fix CVE-2023-20569 in linux-firmware for RHEL 8.2 Advanced Update Support, Telecommunications Update Service, and Update Services for SAP Solutions.
RHSA-2024:0113 and RHSA-2024:0134 fixed CVE-2023-20569 in RHEL 8 kernel and kernel-rt packages, respectively.
Red Hat issued RHSA-2023:7782 for RHEL Server AUS 7.6 on x86_64, updating linux-firmware to remediate the Inception and Zenbleed information-disclosure vulnerabilities.
RHSA-2023:5419 provided a kernel fix for CVE-2023-20593 in the RHEL 7.7 Advanced Update Support stream.
Red Hat released RHSA-2023:5244 and RHSA-2023:5255 to fix CVE-2023-20593 in RHEL 8 kernel and kernel-rt packages.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
access.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourceaccess.redhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourcebugzilla.redhat.com
Open sourceredhat.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.