CVE-2025-54518Disclosure

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1189CWE-1220

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 7 signals
  • Disclosure: 6 classified signals
  • Peaked 4d ago at 2 mentions (2026-05-13); latest day: 1
  • 7 total mentions across 5 days

Deep dive

Activity timeline7 mentions / 5d
01122Mentions · 2026-05-13: 2Mentions · 2026-05-14: 1Mentions · 2026-05-15: 2Mentions · 2026-05-16: 1Mentions · 2026-06-24: 1Patch / Workaround · 2026-05-14: 1Technical Details · 2026-05-13: 2Technical Details · 2026-05-14: 1Technical Details · 2026-05-15: 2Technical Details · 2026-05-16: 1Technical Details · 2026-06-24: 105-1305-1405-1505-1606-24
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-05-132
Disclosure2
2026-05-141
Patch1
2026-05-152
Disclosure2
2026-05-161
Disclosure1
2026-06-241
Disclosure1
Full discourse7 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Xen Security Advisory 490 v1 (CVE-2025-54518) - x86: CPU Opcode Cache corruption https://www.openwall.com/lists/oss-security/2026/05/12/15 AMD Fam17h CPUs (Zen2 microarchitecture) are vulnerable. Code of any privilege could escalate to a higher privilege, including userspace to kernel, and guest to host.

    Post summary

    CVE-2025-54518, a CPU opcode cache corruption issue on AMD Zen2 CPUs, is disclosed with details on privilege escalation, yet no PoC, exploit code, active exploitation, or patch information is provided.

    050722.6K
    4.7K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    AMD Zen 2 processors (Ryzen/EPYC) hit by CVE-2025-54518. Hardware flaw allows instruction corruption and privilege escalation. Update your BIOS now! #AMD #Zen2 #Ryzen #EPYC #CyberSecurity #InfoSec #HardwareSecurity #Vulnerability #TechNews #BIOSUpdate #CPU https://securityonline.info/amd-zen-2-cpu-vulnerability-cve-2025-54518-privilege-escalation/ https://t.co/nrHC1N3H0v

    Post summary

    The post highlights a hardware flaw in AMD Zen 2 processors that enables privilege escalation and urges users to update their BIOS, but no PoC, exploit, or active exploitation claims are mentioned.

    030331.8K
    12.5K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Disclosure

    SUSE-SU-2026:2613-1: 5 CVEs no Xen hypervisor, incluindo CVE-2025-54518 (AMD Zen 2 cache corruption) e CVE-2026-42487 (HVM I/O port traversal). Saiba mais: -> http://tinyurl.com/28ukjuz3 #SUSE https://t.co/AeDxCWV6aA

    Post summary

    SUSE publishes an advisory for five Xen hypervisor CVEs, including cache corruption and I/O port traversal, and links for additional details.

    1000091
    1.5K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『AMD has identified a vulnerability in the CPU operation (op/µop) cache on Zen 2‑based products that can cause incorrect instructions to be executed at a higher privilege level.』 CVE-2025-54518 CPU OP Cache Corruption https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7052.html

    Post summary

    AMD has disclosed CVE‑2025‑54518, a CPU op/µop cache corruption flaw in Zen 2‑based products that can lead to privilege escalation by executing incorrect instructions.

    100001.5K
    6.9K followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2025-54518 | Microsoft Windows up to Server 2025 CPU OP Cache privilege escalation (EUVD-2025-209882 / Nessus ID 314333) https://ift.tt/aMOkDIZ A vulnerability described as problematic has been identified in Microsoft Windows. The affected element is an unknown function of…

    Post summary

    A newly identified privilege escalation vulnerability (CVE-2025-54518) affecting Microsoft Windows up to Server 2025 through the CPU OP Cache has been disclosed, but no PoC, exploit code, active exploitation, or patch information is provided.

    000001.6K
    974 followersView on X
  • Israel@f1tym1
    Disclosure

    CVE-2025-54518 | Microsoft Windows up to Server 2025 CPU OP Cache privilege escalation (Nessus ID 314333 / WID-SEC-2026-1489) https://ift.tt/rLmYiDj A vulnerability described as problematic has been identified in Microsoft Windows. The affected element is an unknown function o…

    Post summary

    The text announces CVE-2025-54518, a privilege escalation vulnerability in the CPU Op Cache of Windows Server 2025, but provides limited technical detail and no evidence of active exploitation or mitigation.

    000001.4K
    974 followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『Code of any privilege could escalate to a higher privilege, including userspace to kernel, and guest to host.』 CVE-2025-54518 XSA-490 - Xen Security Advisories https://xenbits.xen.org/xsa/advisory-490.html

    Post summary

    The snippet highlights a privilege‑escalation vulnerability (CVE‑2025‑54518) that allows code at any privilege level to be elevated, including userspace to kernel and guest to host, and references Xen’s XSA‑490 advisory.

    000001.2K
    6.9K followersView on X

Explore more