Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2025-54505

Опубликовано: 27 апр. 2026
Источник: debian
EPSS Низкий

Описание

A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
xenfixed4.20.3+127-gc42374a105-1package
xenno-dsabookwormpackage
xenend-of-lifebullseyepackage

Примечания

  • AMD CPU HW issue:

  • https://www.amd.com/en/resources/product-security/bulletin/amd-sb-7053.html

  • https://roots.ec/blog/fpdss/

  • Mitigation in src:xen and src:linux:

  • https://xenbits.xen.org/xsa/advisory-488.html

  • https://git.kernel.org/linus/e55d98e7756135f32150b9b8f75d580d0d4b2dd3

  • The Linux kernel has its own CVE CVE-2026-31628 for the lack of mitigation, and

  • thus only tracked under CVE-2026-31628.

EPSS

Процентиль: 9%
0.00191
Низкий

Связанные уязвимости

ubuntu
4 месяца назад

A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.

CVSS3: 3.3
redhat
5 месяцев назад

A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.

nvd
4 месяца назад

A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.

github
4 месяца назад

A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.

suse-cvrf
4 месяца назад

Security update for xen

EPSS

Процентиль: 9%
0.00191
Низкий