CVE-2025-54505
Received
Received - Intake
Transient Execution Data Leak via AMD CPU Floating Point Unit
Publication date: 2026-04-27
Last updated on: 2026-04-29
Assigner: Advanced Micro Devices Inc.
Description
Description
A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| amd | cpu | * |
| amd | epyc_7001_series | * |
| amd | epyc_embedded_3000_series | * |
| amd | athlon_3000_series_with_radeon_graphics | * |
| amd | ryzen_3000_series_with_radeon_graphics | * |
| amd | ryzen_pro_3000_series_with_radeon_vega_graphics | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-UNKNOWN |