Executive brief
A vulnerability in certain AMD Zen 2 processors could allow a malicious user or a virtual machine to gain unauthorized control over the entire system. By exploiting a flaw in how the processor handles its internal instruction cache, an attacker can corrupt commands being executed by more secure parts of the system, such as the operating system kernel or a virtualization host. This could lead to a total compromise of data confidentiality and system integrity on affected hardware.
Technical details
This vulnerability (CWE-1189) stems from improper isolation of shared resources within the CPU operation (opcode) cache on AMD Zen 2 (Family 17h) microarchitectures. A local attacker with low privileges can exploit this flaw to corrupt instructions being executed at higher privilege levels. In virtualized environments, such as those running the Xen hypervisor, this can facilitate guest-to-host escapes or userspace-to-kernel privilege escalation. The attack requires local access and is characterized by high complexity due to the nature of CPU cache timing and instruction corruption. AMD has released microcode updates, and Xen has provided patches for versions 4.17 through 4.21 to mitigate the issue.
Affected products
- AMD EPYC 7002 Series Processors
- AMD Ryzen 3000 Series Desktop Processors
- AMD Ryzen 4000 Series Mobile Processors with Radeon Graphics
- AMD Ryzen 5000 Series Mobile Processors with Radeon Graphics
- AMD Ryzen 7020 Series Processors with Radeon Graphics
- AMD Ryzen 7030 Series Mobile Processors with Radeon Graphics
- AMD Ryzen Threadripper PRO 3000 WX-Series Processors
- Xen Project Xen 4.17, 4.18, 4.21
Timeline
- 2026-05-12: disclosed: Xen Project released advisory XSA-490
- 2026-05-15: advisory: NVD published CVE-2025-54518
- 2026-05-12: patched: Xen patches released for multiple versions
References
- https://www.amd.com/en/resources/product-security/bulletin/AMD-SB-7052.html
- http://www.openwall.com/lists/oss-security/2026/05/12/15
- http://xenbits.xen.org/xsa/advisory-490.html
- https://access.redhat.com/security/cve/CVE-2025-54518
- https://bugzilla.redhat.com/show_bug.cgi?id=2477784
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-54518.json