Junglewise Threat Intelligence

CVE-2025-68195: Linux Kernel out-of-bounds access in AMD Zen 5 microcode matching

CVE-2025-68195 · Severity: high · CVSS 7.1 · Published 2025-12-16

Technologies: Linux. Vendors: Linux.

Executive brief

A vulnerability in the Linux kernel affects systems using AMD Zen 5 processors. The issue occurs when the system checks for specific processor updates, potentially leading to an unstable state or unauthorized access to system memory. This could result in a complete system crash or allow a local user to access sensitive information stored in memory.

Technical details

An out-of-bounds (OOB) memory access vulnerability exists in the Linux kernel's x86 CPU initialization code for AMD Zen 5 processors. The `zen5_rdseed_microcode` array lacked a null terminator, causing the `x86_match_min_microcode_rev()` function to iterate past the end of the defined array. This flaw can be triggered during CPU initialization or microcode matching, potentially leading to a kernel panic (DoS) or information leakage from adjacent memory. The issue has been resolved by adding the missing empty struct terminator to the array in the `arch/x86/kernel/cpu/amd.c` file. Fixes are available in stable kernel updates.

Affected products

  • Linux Linux 6.12.58, 6.13

Timeline

  • 2025-11-04: patched: Initial patch submitted by AMD developers
  • 2025-12-16: disclosed: CVE published

References