
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68313 is a Linux kernel vulnerability affecting AMD Zen5 processors, specifically related to the RDSEED instruction's 16-bit and 32-bit register output variants. These variants return a random value of 0 at a rate inconsistent with true randomness while incorrectly signaling success (CF=1), undermining the reliability of hardware random number generation. The vulnerability was disclosed on December 16, 2025, and is tracked under AMD security bulletin AMD-SB-7055. It carries a CVSS v3.1 base score of 5.5 (Medium), with a high availability impact and no confidentiality or integrity impact (Red Hat Advisory, Red Hat Bugzilla).
The root cause is a hardware-level defect in AMD Zen5 processors where the RDSEED instruction's 16-bit and 32-bit output modes produce biased output (frequently returning 0) while the carry flag (CF=1) incorrectly signals that a valid random seed was generated. This constitutes a failure of the hardware entropy source, classified broadly as improper output generation (related to CWE-330: Use of Insufficiently Random Values). The Linux kernel fix adds microcode revision checking to detect affected Zen5 CPUs and applies a software workaround ("fix glue") to compensate for the faulty hardware behavior. The attack vector is local, requiring low privileges, and no user interaction is needed (Red Hat Bugzilla, Red Hat Advisory).
The primary impact is on availability of cryptographic random number generation on systems running AMD Zen5 processors, as applications relying on RDSEED for entropy may receive predictably weak seeds without any error indication. This could degrade the quality of cryptographic key generation, session tokens, or other security-sensitive operations that depend on hardware randomness. While direct confidentiality and integrity impacts are rated as none in the CVSS scoring, the downstream effect on cryptographic operations could indirectly weaken security guarantees in affected environments (Red Hat Advisory, Red Hat Bugzilla).
Patches are available in Linux kernel versions 6.12.58, 6.17.8, and 6.18, which introduce microcode revision checking and a software fix for the RDSEED instruction on affected Zen5 processors. Users should update to one of these patched kernel versions as the primary remediation. Additionally, applying the latest AMD microcode updates is recommended to address the underlying hardware issue. Systems that cannot be immediately patched should monitor for unexpected behavior in cryptographic operations relying on hardware entropy (Red Hat Advisory, Red Hat Bugzilla).
The vulnerability was reported via the standard Linux kernel CVE announcement process and tracked by Red Hat's Product Security team. AMD published a related security bulletin (AMD-SB-7055) describing the hardware defect. Coverage has been limited to vulnerability databases and security tracking platforms, with no notable broader media or researcher commentary identified (Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."