{"id":8169,"date":"2025-11-04T10:04:13","date_gmt":"2025-11-04T10:04:13","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/11\/04\/amd-zen-5-processors-rdseed-vulnerability-breaks-integrity-with-randomness\/"},"modified":"2025-11-04T10:04:13","modified_gmt":"2025-11-04T10:04:13","slug":"amd-zen-5-processors-rdseed-vulnerability-breaks-integrity-with-randomness","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/11\/04\/amd-zen-5-processors-rdseed-vulnerability-breaks-integrity-with-randomness\/","title":{"rendered":"AMD Zen 5 Processors RDSEED Vulnerability Breaks Integrity With Randomness"},"content":{"rendered":"<p>    AMD Zen 5 Processors RDSEED Vulnerability Breaks Integrity With Randomness<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>AMD has disclosed a critical vulnerability affecting its Zen 5 processor lineup that compromises the reliability of random number generation, a fundamental security feature in modern computing.<\/p>\n<p>The flaw, tracked as CVE-2025-62626, impacts the RDSEED instruction used by systems to generate cryptographically secure random numbers essential for <a href=\"https:\/\/cybersecuritynews.com\/what-are-the-best-encryption-integrations-for-microsoft-365\/\" target=\"_blank\" rel=\"noreferrer noopener\">encryption<\/a>, authentication, and other security operations.<\/p>\n<p>The vulnerability stems from a defect in the RDSEED instruction implementation on Zen 5 processors. Under certain conditions, the instruction returns a value of zero while incorrectly signaling success through the carry flag (CF=1).<\/p>\n<p>This behavior creates a dangerous scenario where software believes it has received a valid random number when it has actually obtained a predictable zero value. The issue affects both 16-bit and 32-bit forms of the RDSEED instruction, though the 64-bit version remains unaffected.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-understanding-the-rdseed-flaw\"><strong>Understanding the RDSEED Flaw<\/strong><\/h2>\n<p>AMD learned about this bug through an unconventional channel. The issue was first reported publicly on the <a href=\"https:\/\/cybersecuritynews.com\/linux-kernal-6-13\/\" target=\"_blank\" rel=\"noreferrer noopener\">Linux kernel<\/a> mailing list rather than through AMD\u2019s standard Coordinated Vulnerability Disclosure process.<\/p>\n<p>This public disclosure path highlights the collaborative nature of open-source security research but also underscores the challenge of managing security information across diverse reporting channels.<\/p>\n<p>The severity of this vulnerability cannot be understated. Random number generation forms the backbone of cryptographic security in modern systems.<\/p>\n<p>When RDSEED fails silently by returning zeros while indicating success, applications may generate weak encryption keys, predictable authentication tokens, or compromised <a href=\"https:\/\/cybersecuritynews.com\/how-esim-technology-enhances-security-protocols\/\" target=\"_blank\" rel=\"noreferrer noopener\">security protocols<\/a>.<\/p>\n<figure class=\"wp-block-table is-style-stripes\">\n<table class=\"has-fixed-layout\">\n<thead>\n<tr>\n<th>CVE<\/th>\n<th>CVE Description<\/th>\n<th>CVSS Score<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>CVE-2025-62626<\/td>\n<td>Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.<\/td>\n<td>7.2 (High) CVSS:4.0\/AV:L\/AC:L\/AT:P\/PR:L\/UI:N\/VC:H\/VI:H\/VA:N\/SC:N\/SI:N\/SA:N<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<\/figure>\n<p>An attacker with local system access could potentially exploit this weakness to predict or influence cryptographic operations, leading to <a href=\"http:\/\/cybersecuritynews.com\/salesloft-drift-data-breaches\/\">data breaches<\/a> or unauthorized access.<\/p>\n<p>System administrators can utilize the 64-bit form of RDSEED exclusively, mask the RDSEED capability from software detection by modifying boot parameters, or implement software logic to treat zero returns as failures requiring retry attempts. The company plans to <a href=\"https:\/\/www.amd.com\/en\/resources\/product-security\/bulletin\/amd-sb-7055.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">release<\/a> microcode updates and AGESA firmware revisions across its product portfolio.<\/p>\n<p>AMD EPYC 9005 Series processors will receive updates by mid-November 2025, while consumer Ryzen 9000 Series, Ryzen AI 300 Series, and Threadripper 9000 processors target late November releases. Embedded processor variants will see patches deployed through January 2026.<\/p>\n<p>Organizations running affected Zen 5 systems should prioritize applying these updates once available through their original equipment manufacturers.<\/p>\n<p>Until patches are deployed, implementing the recommended software workarounds provides essential protection against potential exploitation of this random integrity vulnerability.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/amd-zen-5-rdseed-vulnerability\/\">AMD Zen 5 Processors RDSEED Vulnerability Breaks Integrity With Randomness<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/amd-zen-5-rdseed-vulnerability\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>AMD Zen 5 Processors RDSEED Vulnerability Breaks Integrity With Randomness AMD has disclosed a critical vulnerability affecting its Zen 5 processor lineup that compromises the reliability of random number generation, a fundamental security feature in modern computing. The flaw, tracked as CVE-2025-62626, impacts the RDSEED instruction used by systems to generate cryptographically secure random numbers [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,131],"tags":[130],"class_list":["post-8169","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8169"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=8169"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/8169\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=8169"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=8169"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=8169"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}