CVE-2025-54505 PUBLISHED

Assigner: AMD
Reserved: 23.07.2025 Published: 27.04.2026 Updated: 27.04.2026

A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 2

Product Status

Vendor AMD
Product AMD EPYC™ 7001 Series Processors
Versions Default: affected
  • Version OS update is unaffected
Vendor AMD
Product AMD EPYC™ Embedded 3000 Series Processors
Versions Default: affected
  • Version OS Update is unaffected

References

Problem Types

  • CWE-1420 Exposure of Sensitive Information during Transient Execution CWE