CVE-2020-12965
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 2.4%
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
nono source reports it
In short
AMD CPUs can briefly execute memory operations using incomplete addresses, potentially allowing attackers to read sensitive data that shouldn't be accessible.
Technical detail
This vulnerability exploits transient execution in AMD processors where non-canonical address loads/stores are temporarily executed using only the lower 48 bits, bypassing address validation. Exploitation requires specific software sequences combined with cache timing side-channels; the impact is potential data leakage from restricted memory regions.
Summary generated and translated by AI from the official description.
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.
Affected products
AMD · All supported processors