CVE-2025-54505

LOW

AMD EPYC 7001 Series - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-54505. PoCs published by siltyy.

AI-analyzed exploit summary This repository contains a Linux kernel module that mitigates CVE-2025-54505 by setting a specific MSR bit (0xC0011028, bit 9) as described in AMD-SB-7053. The module is designed to apply the fix at initialization and includes proper error handling.

Description

A transient execution vulnerability within AMD CPUs may allow a local user-privileged attacker to leak data via the floating point divisor unit, potentially resulting in loss of confidentiality.

Exploits (1)

nomisec WORKING POC
by siltyy · poc
https://github.com/siltyy/cve-2025-54505-fix

This repository contains a Linux kernel module that mitigates CVE-2025-54505 by setting a specific MSR bit (0xC0011028, bit 9) as described in AMD-SB-7053. The module is designed to apply the fix at initialization and includes proper error handling.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Linux kernel (specific version not specified)
Auth required
Prerequisites: Linux kernel headers · root access to load the module
devstral-2 · analyzed Apr 28, 2026 Full analysis →

Scores

CVSS v4 2.0
EPSS 0.0001
EPSS Percentile 1.5%
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-1420
Status published
Products (2)
AMD/AMD EPYC™ 7001 Series Processors OS update
AMD/AMD EPYC™ Embedded 3000 Series Processors OS Update
Published Apr 27, 2026
Tracked Since Apr 27, 2026