CVE-2025-54510
Missing lock check in AMD Platform Security Processor in AMD EPYC™ 9005 Series CPUs allows a privileged attacker to potentially impact guest confidentiality via local access.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.9
- CVSS vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N
- EPSS probability
- 0.11%
- CWE
- CWE-414
- Published
- 2026-04-16
- Last modified
- 2026-05-13
Affected products
- AMD AMD EPYC™ 9004 Series Processors
- AMD AMD EPYC™ 7003 Series Processors
- AMD AMD EPYC™ 9005 Series Processors
- AMD AMD EPYC™ 8004 Series Processors
- AMD AMD EPYC™ Embedded 7003 Series Processors
- AMD AMD EPYC™ Embedded 9004 Series Processors
- AMD AMD EPYC™ Embedded 9004 Series Processors
- AMD AMD EPYC™ Embedded 8004 Series Processors
Weakness type
Related vulnerabilities
- CVE-2026-54906 — concurrent-ruby: ReadWriteLock allows wrong-thread write release and stray read-release counter corruption
- CVE-2025-54625 — Race condition vulnerability in the kernel file system module....
- CVE-2023-5447 — Use-After-Free in Service for Hardware Support App for Fingerprint Driver