CVE-2025-54505Disclosure

LOWCVSS 2.0 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.

0.5/ 10 priority

Sources & remediation

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 4d ago at 1 mentions (2026-04-17); latest day: 1
  • 5 total mentions across 5 days

Deep dive

Activity timeline5 mentions / 5d
00111Mentions · 2026-04-17: 1Mentions · 2026-04-18: 1Mentions · 2026-04-19: 1Mentions · 2026-04-27: 1Mentions · 2026-07-01: 1Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-07-01: 1Technical Details · 2026-04-17: 1Technical Details · 2026-04-18: 1Technical Details · 2026-04-19: 1Technical Details · 2026-04-27: 104-1704-1804-1904-2707-01
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-171
Disclosure1
2026-04-181
General1
2026-04-191
Disclosure1
2026-04-271
Disclosure1
2026-07-011
Patch1
Full discourse5 posts
  • Daniel Weber@weber_daniel
    Disclosure

    ur most significant finding is Floating Point Divider State Sampling (CVE-2025-54505), which we also discuss in a short blog post. FP-DSS allows an attacker to leak data from the CPU's floating-point division unit. https://t.co/JyQ1smgVeD

    Post summary

    The tweet announces the discovery of CVE‑2025‑54505, a floating‑point division state sampling vulnerability that can leak CPU data, and points to a short blog post for further details.

    2101101.7K
    512 followersView on X
  • Ian Smith@IanSmith_HSA
    General

    Grok answered "Yes" which means possibly not a waste of time to check. "Yes, FP-DSS (CVE-2025-54505) could potentially affect FALCON private keys in certain implementations, but the risk is limited, context-dependent, and likely mitigable. "

    Post summary

    The text references CVE-2025-54505 as potentially impacting FALCON private keys with limited, mitigable risk, but provides no PoC, exploit, or patch details.

    01060789
    4.6K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    USN-8488-1: 70+ CVEs corrigidas no kernel Ubuntu 26.04, incluindo CVE-2025-54505 (AMD speculation). Atenção: mudança de ABI exige recompilação de módulos DKMS. Saiba mais: -> http://tinyurl.com/5r8ub829 #Ubuntu https://t.co/kGJiKKAeRF

    Post summary

    The tweet announces Ubuntu’s kernel update USN-8488-1, which patches over 70 CVEs including CVE-2025-54505, and advises users that ABI changes require DKMS module recompilation.

    1000077
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-54505 A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting… https://www.cve.org/CVERecord?id=CVE-2025-54505

    Post summary

    The post announces CVE-2025-54505, a transient execution flaw in AMD CPUs that could allow local users to leak data via the floating point divisor unit, with no further exploitation or mitigation details provided.

    00010330
    57.3K followersView on X
  • GGSec@GGASecDe
    Disclosure

    AMD-SB-7053 – Floating Point Divider State Sampling (FP-DSS) Allows leaking previous SSE/AVX floating-point division operands (even from other SMT threads). Published 17 Apr 2026 | CVE-2025-54505 (Low severity) Mitigation: set bit 9 in MSR 0xC0011028 #AMD #FP-DSS #CPUSecurity

    Post summary

    The post announces CVE‑2025‑54505, details the floating‑point state leakage flaw, and cites a specific mitigation in the processor’s MSR.

    00010330

Explore more