CVE-2025-54518
🟡 Monitoruj
Niewłaściwa izolacja zasobów w pamięci podręcznej CPU Zen 2 może prowadzić do eskalacji uprawnień.
CVSS
7.0
EPSS
0.3%
Exploit
none
Vendor
Opis źródłowy (NVD)
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
privilege-escalation
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 0.3% |
| Opublikowano (NVD) | 2026-05-15 05:16:33 UTC |
| Ostatnia modyfikacja (NVD) | 2026-08-27 13:16:37 UTC |
Referencje
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-7052.html (psirt@amd.com)
- http://www.openwall.com/lists/oss-security/2026/05/12/15 (af854a3a-2127-422b-91ae-364da2661108)
- http://xenbits.xen.org/xsa/advisory-490.html (af854a3a-2127-422b-91ae-364da2661108)
- https://access.redhat.com/errata/RHSA-2026:50978 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:50979 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:53329 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:53989 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:53990 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:54769 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:55444 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:56573 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:57402 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:57457 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:57543 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/errata/RHSA-2026:59091 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://access.redhat.com/security/cve/CVE-2025-54518 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://bugzilla.redhat.com/show_bug.cgi?id=2477784 (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-54518.json (0b0ca135-0b70-47e7-9f44-1890c2a1c46c)