CVE-2025-62626: High severity AMD RDSEED (AMD CPUs) vulnerability
Published Nov 21, 2025
·Updated
Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.
Affected Software
2 affected componentsFixes available
AMD RDSEED (AMD CPUs)
debian/amd64-microcode<=3.20240820.1~deb11u1, <=3.20250311.1~deb11u1, <=3.20250311.1~deb12u1, <=3.20230719.1~deb12u1, <=3.20250311.1
3.20251202.1
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/amd64-microcodeto a version that resolves this vulnerability.Fixed in 3.20251202.1
Event History
Nov 5, 2025
News Published
via The Register·03:01 PM
News Published
via The Register·03:04 PM
Nov 21, 2025
CVE Published
via MITRE·06:52 PM
Data Sourced
via MITRE·06:52 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeakness
Jun 25, 2026
Data Sourced
via Debian·06:27 PM
DescriptionAffected Software
Jun 26, 2026
Data Sourced
via Ubuntu·06:26 PM
RemedyDescriptionSeverityAffected Software
Jun 29, 2026
Data Sourced
via Launchpad·06:30 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2025-62626?
CVE-2025-62626 has a high severity rating of 7.2.
2
What are the potential risks associated with CVE-2025-62626?
CVE-2025-62626 may allow local attackers to influence the RDSEED instruction, compromising randomness.
3
How do I mitigate CVE-2025-62626?
To mitigate CVE-2025-62626, ensure your AMD CPU microcode is updated to the latest version.
4
Who is affected by CVE-2025-62626?
CVE-2025-62626 affects users of AMD CPUs that utilize the RDSEED instruction.
5
When was CVE-2025-62626 published?
CVE-2025-62626 was published on November 21, 2025.