CVE-2025-62626Patch

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-333

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-17); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-17: 1Mentions · 2026-09-23: 1Patch / Workaround · 2026-03-17: 1Technical Details · 2026-03-17: 1Technical Details · 2026-09-23: 103-1709-23
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-03-171
Patch1
2026-09-231
Disclosure1
Full discourse2 posts
  • First Sauce Labs@first_sauce_lab
    Disclosure

    On several AMD chips, RDRAND never returns a zero at 16-bit width. A flat assembler thread since May covers Zen 1 to Zen 5, mixed results. You cannot read an RNG, only sample it. CVE-2025-62626 covers RDSEED losing entropy.

    Post summary

    The text discloses technical details regarding CVE-2025-62626, linking it to AMD RDSEED entropy loss and RDRAND behavior across Zen architectures, but provides no exploit, patch, or active exploitation evidence.

    0000094
    29 followersView on X
  • ThreatCluster@threatcluster
    Patch

    Qualys reports Linux kernel flaws in AppArmor LSM and AMD Zen 5 RDSEED (CVE-2025-62626), enabling local privilege escalation and poor randomness. Patch Ubuntu 24.04 and 25.10. #Linux https://threatcluster.io/cluster/critical-linux-kernel-vulnerabilities-discovered-affecting-a-b0d11b1e

    Post summary

    Qualys reported CVE-2025-62626, a Linux kernel flaw enabling local privilege escalation through AppArmor LSM and AMD Zen 5 RDSEED; Ubuntu 24.04 and 25.10 users are urged to apply the latest patches.

    00000154
    104 followersView on X

Explore more