CVE-2025-54514
Linux Debian vulnerability analysis and mitigation

Overview

CVE-2025-54514 is an improper isolation of shared resources on a System-on-Chip (SoC) vulnerability affecting multiple AMD processor families. A malicious local attacker with elevated privileges could exploit this flaw to cause a partial loss of integrity. The vulnerability was discovered internally by AMD and publicly disclosed on February 10, 2026, as part of two AMD security bulletins (AMD-SB-3023 and AMD-SB-4013). It carries a CVSS v4.0 base score of 4.8 (Medium) (AMD SB-3023, AMD SB-4013).

Technical details

The vulnerability is classified under CWE-1189 (Improper Isolation of Shared Resources on System-on-a-Chip), which occurs when hardware components on a SoC do not adequately isolate shared resources between different privilege domains or execution contexts. An attacker with local access and at least low-level privileges can exploit this flaw to manipulate shared SoC resources in a way that partially compromises system integrity. No user interaction is required, and the attack complexity is low, though the impact is limited to a partial integrity loss with no confidentiality or availability impact. The vulnerability was found internally by AMD during security audits (AMD SB-3023, AMD SB-4013).

Impact

Successful exploitation of CVE-2025-54514 results in a partial loss of integrity on the affected system, with no impact to confidentiality or availability. The attack is confined to the local attack surface and requires an attacker who already has at least low-privilege local access to the system. Given the limited scope — no lateral movement potential and no data exposure risk — the practical impact is constrained, though it could be chained with other vulnerabilities in a multi-stage attack against AMD-based platforms (AMD SB-3023, AMD SB-4013).

Exploitability

There is no public evidence of in-the-wild exploitation of CVE-2025-54514, and no public proof-of-concept exploit code has been identified. The EPSS score is very low at approximately 0.014%, reflecting a minimal probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires local access with at least low privileges, which significantly limits the attacker pool (AMD SB-3023).

Mitigation and workarounds

AMD has released Platform Initialization (PI) firmware updates to address CVE-2025-54514 across multiple product lines. Key mitigations include:

  • AMD EPYC 9005 Series ("Turin"/"Turin Dense"): TurinPI 1.0.0.6 (released 2025-06-30); microcode BRH C1: 0x0B002151 / BRHD B0: 0x0B10104E (released 2025-07-14)
  • AMD EPYC Embedded 9005 Series: EmbTurinPI-SP5 1.0.0.1 (released 2025-10-31)
  • AMD Ryzen 9000 Series Desktop: ComboAM5 PI 1.2.0.3h (released 2025-10-22)
  • AMD Ryzen 9000HX Series Mobile: FireRangeFL1 PI-1.0.0.0d (released 2025-10-26)
  • AMD Ryzen AI 300 Series: StrixKrackanPI-FP8_1.1.0.0d (released 2025-09-04)
  • AMD Ryzen AI Max 300 Series: StrixHaloPI-FP11_1.0.0.1c (released 2025-08-18)
  • AMD Ryzen Threadripper 9000 / PRO 9000 WX-Series: ShimadaPeakPI-SP6_1.0.0.1b (released 2025-07-28)
  • AMD Ryzen Z2 Series Extreme: StrixKrackanPI-FP8_1.1.0.0d (released 2025-09-04)

Users should contact their OEM for the specific BIOS update applicable to their product. No configuration-based workaround is documented for this CVE (AMD SB-3023, AMD SB-4013).

Community reactions

AMD disclosed CVE-2025-54514 as part of two coordinated security bulletins (AMD-SB-3023 and AMD-SB-4013) published on February 10, 2026, covering a broad set of EPYC, Ryzen, and Athlon processor vulnerabilities. The vulnerability was identified internally by AMD, and no external researcher credit is listed for this specific CVE. Community and media reaction has been limited given the moderate severity and local-only attack vector, with aggregator sites such as VulDB and CVEFeed.io tracking the disclosure without notable commentary (AMD SB-3023, AMD SB-4013).

Additional resources

  • AMD SB-3023 — AMD EPYC Processor Vulnerabilities – February 2026
  • AMD SB-4013 — AMD Athlon/Ryzen Processor Vulnerabilities – February 2026
  • Lenovo Advisory — Lenovo product security advisory referencing CVE-2025-54514
  • Tenable Plugin — Nessus detection plugin for CVE-2025-54514
  • AWS ALAS — Amazon Linux Security Advisory referencing this CVE
  • Thomas-Krenn AMD-SB-4013 — Third-party advisory summary for AMD-SB-4013

SourceThis report was generated using AI

Related Linux Debian vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45699HIGH7.5
  • Linux Debian logoLinux Debian
  • netatalk
NoYesAug 14, 2026
CVE-2026-73051MEDIUM6.3
  • Linux Debian logoLinux Debian
  • rust-actix-http
NoYesAug 14, 2026
CVE-2026-47766MEDIUM5.1
  • Linux Debian logoLinux Debian
  • crun
NoYesAug 14, 2026
CVE-2026-47192LOW2.1
  • Python logoPython
  • kas
NoYesAug 14, 2026
CVE-2026-47191LOW2.1
  • Python logoPython
  • kas
NoYesAug 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management