CVE-2019-20569
NixOS vulnerability analysis and mitigation

Overview

CVE-2023-20569, also known as Return Address Predictor (or Inception), is a speculative side channel attack vulnerability that can result in speculative execution at an attacker-controlled address. This vulnerability affects certain AMD processors and was disclosed on August 8, 2023. The vulnerability might potentially lead to information disclosure (Microsoft KB).

Technical details

The vulnerability is a speculative side channel attack that affects AMD processors. It requires CPU microcode/firmware updates for mitigation. The vulnerability allows speculative execution at an attacker-controlled address, which could lead to information disclosure. For Windows systems, the mitigation is not enabled by default and requires specific registry configurations to be enabled (Microsoft KB).

Impact

The vulnerability could potentially lead to information disclosure through speculative execution at attacker-controlled addresses on affected AMD processors (NVD).

Mitigation and workarounds

To mitigate this vulnerability, systems require both Windows updates dated August 2023 or later and CPU microcode updates from AMD. For Windows systems, specific registry settings must be configured to enable the mitigation. The registry key settings include adding FeatureSettingsOverride with value 67108928 and FeatureSettingsOverrideMask with value 3 (Microsoft KB).

Additional resources


SourceThis report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-69264CRITICAL9.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69263HIGH8.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-69262HIGH7.8
  • JavaScriptJavaScript
  • pnpm
NoYesJan 07, 2026
CVE-2025-20807MEDIUM6.7
  • NixOSNixOS
  • android
NoNoJan 06, 2026
CVE-2026-21885MEDIUM6.5
  • NixOSNixOS
  • miniflux
NoYesJan 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management