Vulnerability Intelligence Report
CVE-2025-62626
Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.
No Active Exploit Signals
CVSS Base Score
7.2
HIGH
EPSS Probability:0.16%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-333 ↗CWE-333 Improper Handling of Insufficient Entropy in TRNG
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| AMD | AMD Ryzen™ 9000HX Series Processors | FireRangeFL1PI 1.0.0.0e (unaffected) |
| AMD | AMD EPYC™ 9005 Series Processors | Turin C1 : 0x0B00215A Turin Dense / B0: 0x0B101054 (unaffected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.156%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Advanced Micro Devices Inc. · Vendor · USA |
| Reserved | 2025-10-16T20:46:13 |
| Published | 2025-11-21T18:52:57 |
| Patch Date | 2025-11-21 |
| Last Updated | 2026-02-26T16:07:38 |
Community Chatter & Buzz