AMD EPYC Venice Zen 6 CPUs Surface in QEMU Patch With New Security Fix and AI-Focused Instructions
AMD’s next-generation EPYC “Venice” server processors are starting to take shape ahead of their official reveal. A newly submitted QEMU patch from an AMD engineer has provided one of the clearest early looks yet at the Zen 6 EPYC platform, confirming key CPU identification data, cache details, instruction set upgrades, and a notable hardware-level fix for a known speculative-execution vulnerability.
The patch adds an official “Epyc-Venice” CPU model to QEMU’s x86 emulation code, giving developers and operating systems a defined target for AMD’s upcoming server chips. The processor is identified as family 26, model 80, stepping 0, and appears to guest operating systems as the “AMD EPYC-Venice Processor.”
That alone is significant, but the more interesting details are found in the feature list. EPYC Venice builds on the foundation of AMD’s current Zen 5 “Turin” server CPUs while adding several new instruction set extensions aimed at accelerating modern workloads. These include AVX512 FP16, AVX-IFMA, AVX-NE-CONVERT, AVX-VNNI-INT8, and a new AVX512 Bit Matrix Multiply instruction.
These additions point strongly toward improved performance in AI, machine learning, high-performance computing, data analytics, and other server-heavy tasks where vector and matrix math are critical. With AI workloads continuing to reshape the data center market, these Zen 6 EPYC processors appear designed to strengthen AMD’s position in performance-per-watt and compute density.
One of the most important discoveries in the QEMU patch is the presence of SRSO_NO, which indicates that EPYC Venice is not vulnerable to Speculative Return Stack Overflow. SRSO is a speculative-execution security issue that affected earlier Zen architectures by exploiting how the CPU predicts return addresses during execution.
In simple terms, the vulnerability could trick a processor into speculatively running code from an attacker-influenced location before the CPU realizes the prediction was wrong. Previous protections relied mainly on software mitigations, such as flushing branch prediction data during context switches. While effective, those software-based defenses can introduce performance overhead.
With Zen 6 EPYC Venice, AMD appears to be addressing this issue directly in hardware. That means the processor can avoid the vulnerability without depending as heavily on software workarounds, potentially preserving more performance in security-sensitive server environments.
The patch also introduces Enhanced Return Address Prediction Security, or ERAPS. This appears to be a new protection mechanism related to how return address prediction history is managed, especially in virtualized environments. For cloud providers, enterprise virtualization, and multi-tenant server deployments, this kind of hardware-level security improvement could be especially valuable.
An independently submitted lscpu output from an EPYC Venice engineering sample supports the QEMU patch details, listing the system as “not affected” by speculative return stack overflow. That confirmation suggests the information is not only theoretical or emulator-focused, but also reflected in real silicon currently being tested.
The cache layout revealed in the patch shows that AMD is keeping several core-level cache structures familiar from Zen 5 EPYC Turin. Each core includes a 48 KB 12-way L1 data cache and a 32 KB 8-way L1 instruction cache. The L2 cache remains 1 MB per core, 16-way and inclusive. At the die level, the L3 cache is listed as 64 MB, 16-way shared cache.
While those cache figures do not represent a major visible change from the previous generation, the architectural improvements, new instructions, and security upgrades may still deliver meaningful gains across server workloads. Zen 6 is expected to focus not only on raw performance, but also on efficiency, AI acceleration, and platform-level improvements.
The newly surfaced details do not include memory specifications, core counts, socket information, pricing, or release timing. However, AMD has already indicated that EPYC Venice will be officially introduced during its Advancing AI event in San Francisco on July 22–23. That means full specifications and availability details are likely just around the corner.
For data center customers, cloud providers, and enterprise buyers, EPYC Venice is shaping up to be a major server CPU launch. The combination of Zen 6 architecture, expanded AVX-512 capabilities, AI-oriented instructions, and built-in protection against SRSO could make AMD’s next EPYC generation an important upgrade for secure, high-performance computing.
If the early QEMU and engineering-sample data accurately reflect the final product, AMD EPYC Venice may arrive not only as a faster server processor, but as a more secure and AI-ready platform built for the next wave of data center workloads.






