Oleksii Oleksenko, Cedric Fournet, Jana Hofmann, Boris Köpf, Stavros Volos, and Flavien Solt discovered that some AMD processors may allow an attacker to infer data from stores, potentially resulting in the leakage of privileged information. A local attacker could possibly use this to expose sensitive information. ( CVE-2024-36350 , CVE-2024-36357 ) It was discovered that some AMD Zen 5 processors supporting RDSEED instruction did not properly handle entropy, potentially resulting in the consumption of insufficiently random values. A local attacker could possibly use this issue to influence the values returned by the RDSEED instruction causing loss of confidentiality and integrity. ( CVE-2025-62626 )
Oleksii Oleksenko, Cedric Fournet, Jana Hofmann, Boris Köpf, Stavros Volos, and Flavien Solt discovered that some AMD processors may allow an attacker to infer data from stores, potentially resulting in the leakage of privileged information. A local attacker could possibly use this to expose sensitive information. ( CVE-2024-36350 , CVE-2024-36357 )
It was discovered that some AMD Zen 5 processors supporting RDSEED instruction did not properly handle entropy, potentially resulting in the consumption of insufficiently random values. A local attacker could possibly use this issue to influence the values returned by the RDSEED instruction causing loss of confidentiality and integrity. ( CVE-2025-62626 )
Oleksii Oleksenko, Cedric Fournet, Jana Hofmann, Boris Köpf, Stavros Volos, and Flavien Solt discovered that some AMD processors may allow an attacker to infer data from stores, potentially resulting in the leakage of privileged information. A local attacker could possibly use this to expose sensitive information. ( CVE-2024-36350 , CVE-2024-36357 ) It was discovered that some AMD Zen 5 processors supporting RDSEED instruction did not properly handle entropy, potentially resulting in the consumption of insufficiently random values. A local attacker could possibly use this issue to influence the values returned by the RDSEED instruction causing loss of confidentiality and integrity. ( CVE-2025-62626 )
Oleksii Oleksenko, Cedric Fournet, Jana Hofmann, Boris Köpf, Stavros Volos, and Flavien Solt discovered that some AMD processors may allow an attacker to infer data from stores, potentially resulting in the leakage of privileged information. A local attacker could possibly use this to expose sensitive information. ( CVE-2024-36350 , CVE-2024-36357 )
It was discovered that some AMD Zen 5 processors supporting RDSEED instruction did not properly handle entropy, potentially resulting in the consumption of insufficiently random values. A local attacker could possibly use this issue to influence the values returned by the RDSEED instruction causing loss of confidentiality and integrity. ( CVE-2025-62626 )
After a standard system update you need to reboot your computer to make all the necessary changes.
ATTENTION: For the most comprehensive protection, users should update their system BIOS/UEFI to the latest version provided by their hardware vendor. If the BIOS has not been updated, this microcode update will apply the latest available mitigations that can be delivered via the operating system. For more information, please see:
The problem can be corrected by updating your system to the following package versions:
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
Have additional questions?
Talk to a member of the team ›
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
