CVE-2025-68313: x86/CPU/AMD: Add RDSEED fix for Zen5

Published Dec 16, 2025
·
Updated

In the Linux kernel, the following vulnerability has been resolved:

x86/CPU/AMD: Add RDSEED fix for Zen5

There's an issue with RDSEED's 16-bit and 32-bit register output variants on Zen5 which return a random value of 0 "at a rate inconsistent with randomness while incorrectly signaling success (CF=1)". Search the web for AMD-SB-7055 for more detail.

Add a fix glue which checks microcode revisions.

[ bp: Add microcode revisions checking, rewrite. ]

Affected Software

2 affected components
AMD Linux Kernel
Microsoft azl3 kernel 6.6.117.1-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Compensating control

    Check and verify AMD microcode revisions on affected Zen5 systems (RDSEED 16-bit/32-bit register output randomness with incorrect success signaling per AMD-SB-7055); ensure the microcode includes the fix that adds microcode revision checking and the RDSEED fix for Zen5.

Event History

Dec 16, 2025
CVE Published
via MITRE·03:39 PM
Data Sourced
via MITRE·03:39 PM
DescriptionSeverity
Data Sourced
via NVD·04:16 PM
DescriptionSeverity
Dec 18, 2025
Data Sourced
via Microsoft·01:02 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2025-68313?

CVE-2025-68313 has been classified with a severity level that indicates potential risks associated with randomness in cryptographic operations.

2

How do I fix CVE-2025-68313?

To address CVE-2025-68313, ensure that your Linux kernel is updated to a version that includes the recent patches for RDSEED fixes.

3

Which systems are affected by CVE-2025-68313?

CVE-2025-68313 primarily affects systems utilizing the AMD Linux kernel on Zen5 architecture.

4

What impact does CVE-2025-68313 have on system security?

CVE-2025-68313 can potentially weaken cryptographic functions by producing non-random outputs, leading to vulnerabilities in sensitive applications.

5

Is there a workaround for CVE-2025-68313 while waiting for a patch?

Currently, the best mitigation for CVE-2025-68313 is to apply the available patches rather than relying on a specific workaround.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203