← back
CVE-2020-12965

CVE-2020-12965

3Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackepss 2.4%
exploitation probability
2.4%top 17% of all CVEs
observed exploitation
nono source reports it
In short

AMD CPUs can briefly execute memory operations using incomplete addresses, potentially allowing attackers to read sensitive data that shouldn't be accessible.

Technical detail

This vulnerability exploits transient execution in AMD processors where non-canonical address loads/stores are temporarily executed using only the lower 48 bits, bypassing address validation. Exploitation requires specific software sequences combined with cache timing side-channels; the impact is potential data leakage from restricted memory regions.

Summary generated and translated by AI from the official description.
When combined with specific software sequences, AMD CPUs may transiently execute non-canonical loads and store using only the lower 48 address bits potentially resulting in data leakage.