AMD Speculative execution with Floating-Point Value Injection
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.6%
exploitation probability
0.6%top 54% of all CVEs
observed exploitation
nono source reports it
Potential floating point value injection in all supported CPU products, in conjunction with software vulnerabilities relating to speculative execution with incorrect floating point results, may cause the use of incorrect data from FPVI and may result in data leakage.
Affected products
AMD · All supported processorsReferences
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H36U6CNREC436W6GYO7QUMJIVEA35SCV/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SVA2NY26MMXOODUMYZN5DCU3FXMBMBOB/https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1003http://www.openwall.com/lists/oss-security/2021/06/09/2http://www.openwall.com/lists/oss-security/2021/06/10/1