GPU VulnDB

Database/Kernel, userspace & hypervisor

AMD CPU (Inception / SRSO): Inception: Speculative Return Stack Overflow

CVE-2023-20569Kernel, userspace & hypervisorcurated

Impact

Inception: Speculative Return Stack Overflow - attacker-controlled speculative disclosure across privilege domains on Zen 1-4

Who can reach it

Any tenant process in a container; tenant VM guest

What to do

Microcode + kernel mitigation (spec_rstack_overflow=) + reboot. Standing perf cost - the safe-RET mitigation is measurable on syscall-heavy workloads

Fleet impact

How widespread

very common - spans Zen 1 through Zen 4, i.e. essentially every AMD host CPU generation in service

Cost to remediate

microcode+reboot **and** a kernel update (SRSO safe-return / IBPB-on-entry); on Zen 1/2 the mitigation additionally requires **disabling SMT**, which permanently cuts logical core count on those nodes

Why it hits the whole fleet

Kernel-memory disclosure via speculative return redirection across the whole AMD lineup; the SMT-disable mitigation is a capacity hit the operator has to absorb fleet-wide, not a one-time reboot.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.