Executive brief
A vulnerability in the Linux kernel affects systems using AMD Zen 5 processors. The issue occurs when the system checks for specific processor updates, potentially leading to an unstable state or unauthorized access to system memory. This could result in a complete system crash or allow a local user to access sensitive information stored in memory.
Technical details
An out-of-bounds (OOB) memory access vulnerability exists in the Linux kernel's x86 CPU initialization code for AMD Zen 5 processors. The `zen5_rdseed_microcode` array lacked a null terminator, causing the `x86_match_min_microcode_rev()` function to iterate past the end of the defined array. This flaw can be triggered during CPU initialization or microcode matching, potentially leading to a kernel panic (DoS) or information leakage from adjacent memory. The issue has been resolved by adding the missing empty struct terminator to the array in the `arch/x86/kernel/cpu/amd.c` file. Fixes are available in stable kernel updates.
Affected products
- Linux Linux 6.12.58, 6.13
Timeline
- 2025-11-04: patched: Initial patch submitted by AMD developers
- 2025-12-16: disclosed: CVE published