CVE-2025-54518CWE-1189CWE-1220

CVE-2025-54518

High · published May 15, 2026

CVSS v3.1
7.0
EPSS
0%
Percentile
20.9
In the wild
Unconfirmed
What it is

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.

The record
Technical detail
CVSS v3.1
7.0 · HIGH
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.00287 · 20.9th percentile
Weaknesses
CWE-1189 · Improper Isolation of Shared Resources on System-on-a-Chip (SoC); CWE-1220 · Insufficient Granularity of Access Control
Published
2026-05-15T09:16Z
References (20)
https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-7052.html · [email protected]http://www.openwall.com/lists/oss-security/2026/05/12/15 · af854a3a-2127-422b-91ae-364da2661108http://xenbits.xen.org/xsa/advisory-490.html · af854a3a-2127-422b-91ae-364da2661108https://access.redhat.com/errata/RHSA-2026:50978 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:50979 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:53329 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:53989 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:53990 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:54769 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:55444 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:56573 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:57402 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:57457 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:57543 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:59091 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:59831 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/errata/RHSA-2026:60019 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://access.redhat.com/security/cve/CVE-2025-54518 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://bugzilla.redhat.com/show_bug.cgi?id=2477784 · 0b0ca135-0b70-47e7-9f44-1890c2a1c46chttps://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-54518.json · 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
EPSS history
Timeline
  • 15 MAY 03:06Z
    Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a…
    cvelistv5