Insufficient Entropy in AMD products - CVE-2025-62626

 

Insufficient Entropy in AMD products - CVE-2025-62626

Published: October 24, 2025


Vulnerability identifier: #VU117652
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-62626
CWE-ID: CWE-331
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insufficient entropy in Zen 5 processors, which causes the RDSEED instruction to return 0 at a rate inconsistent with randomness while incorrectly signaling success (CF=1), indicating a potential misclassification of failure as success. A local user can escalate privileges on the system.


Affected software

AMD EPYC 9005
AMD EPYC Embedded 9005
Ryzen 9000
Ryzen 9000HX
Ryzen AI 300
Ryzen AI Z2
Ryzen AI Max 300
Ryzen Threadripper 9000
Ryzen Threadripper PRO 9000 WX
Ryzen Z2
AMD EPYC Embedded 4005
Ryzen Embedded 9000
ThinkAgile VX645 V3 Certified Node
ThinkPad P14s Gen 6 21RV
ThinkPad P14s Gen 6 21QM
ThinkPad P14s Gen 6 21QL
ThinkPad L16 Gen 2 21RJ
ThinkPad L16 Gen 2 21RH
ThinkPad L14 Gen 6 21SF
ThinkPad L14 Gen 6 21SE
ThinkAgile VX665 V3 Integrated System
ThinkAgile VX665 V3 Certified Node
ThinkAgile VX655 V3 Integrated System
ThinkAgile VX655 V3 Certified Node
ThinkAgile VX645 V3 Integrated System
ThinkPad P14s Gen 6 21RW
ThinkAgile VX635 V3 Integrated System
ThinkAgile VX635 V3 Certified Node
ThinkAgile HX665 V3 Storage Integrated Node
ThinkAgile HX665 V3 Storage Certified Node
ThinkAgile HX665 V3 Integrated System
ThinkAgile HX645 V3 Certified Node
ThinkAgile HX665 V3 Certified Node
ThinkAgile HX645 V3 Integrated System
Yoga Slim 7 14AKP10
Yoga Pro 7 14ASP9
Yoga Pro 7 14ASP10
ThinkPad T16 Gen 4 21QQ
ThinkSystem ST45 V3
ThinkSystem SR685a V3
ThinkSystem SR675 V3
ThinkSystem SR665 V3
ThinkSystem SR655 V3
ThinkSystem SR645 V3
ThinkSystem SR635 V3
ThinkSystem SD665 V3
ThinkSystem SD535 V3
ThinkStation P8 Workstation
ThinkPad X13 Gen 6 21RN
ThinkPad X13 Gen 6 21RM
ThinkPad T16 Gen 4 21QN
ThinkPad T14s Gen 6 21TC
ThinkPad T14s Gen 6 21TB
ThinkPad T14s Gen 6 21M2
ThinkPad T14s Gen 6 21M1
ThinkPad T14 Gen 6 21QK
ThinkPad T14 Gen 6 21QJ
ThinkPad P16s Gen 4 21RY
ThinkPad P16s Gen 4 21RX
ThinkPad P16s Gen 4 21QS
ThinkPad P16s Gen 4 21QR
Yoga 7 2-in-1 16AKP10
IdeaCentre AIO 24AKP10
Yoga Pro 7 14AKP10
Yoga 7 2-in-1 14AKP10
ThinkBook 16 G7+ ASP
Legion Pro 7 16AFR10H
Legion Pro 5 16AFR10
Legion Go 8ASP2
Legion 5 15AKP10
IdeaPad Slim 5 16AKP10
IdeaPad Slim 5 14AKP10
IdeaPad Pro 5 16ASP10
IdeaPad Pro 5 16AKP10
IdeaPad Pro 5 14AKP10
IdeaPad Pro 5 14ASP10
IdeaCentre AIO 27AKP10
IdeaCentre Tower 08AKP10
Legion T5 30AGB10
LOQ Tower 26ADR10
ThinkCentre Neo 55a 24 Gen 6
ThinkCentre Neo 55q Gen 6
ThinkCentre Neo 55s Gen 6
IdeaPad 5 2-in-1 14AKP10
IdeaPad 5 2-in-1 16AKP10
Flash BIOS Update - ThinkCentre Neo 55a 24 Gen 6, IdeaCentre AIO 27AKP10, AIO 24AKP10
BIOS Update for Windows 11 (64-bit) - Legion Pro7 16AFR10H
System Firmware Update (Utility & Bootable CD) for Windows 11 (64-bit) - ThinkPad T14s Gen 6 (Type 21TB, 21TC)
BIOS Update (Utility & Bootable CD) for Windows 11 (64-bit) - ThinkPad T14s Gen 6 (Type 21TB, 21TC)
BIOS Update (Utility & Bootable CD) for Windows 11 - ThinkPad T14s Gen 6 (Type 21M1, 21M2)
BIOS Update (Utility & Bootable CD) for Windows 11 - ThinkPad P14s Gen 6 (Type 21QL, 21QM, 21RV, 21RW), P16s Gen 4 (Type 21QR, 21QS, 21RX, 21RY), T14 Gen 6 (Type 21QJ, 21QK), T16 Gen 4 (Type 21QN, 21QQ)
System Firmware Update (Utility & Bootable CD) for Windows 11 - ThinkPad L14 Gen 6 (Type 21SE, 21SF), L16 Gen 2 (Type 21RH, 21RJ)
Lenovo System UEFI/BIOS Firmware
BIOS Update for Windows 11 (64-bit) - Yoga Slim 7 14AKP10
BIOS Update for Windows 11 (64-bit) - Yoga Pro 7 14ASP9
BIOS Update for Windows 11 (64-bit) - Yoga Pro 7 14ASP10, Yoga Pro 7 14AKP10
BIOS Update for Windows 11 (64-bit) - Yoga 7 2-in-1 14AKP10, Yoga 7 2-in-1 16AKP10
BIOS Update for Windows 11 (64-bit) - ThinkBook 16 G7+ ASP
BIOS Update for Windows 11 (64-bit) - Legion Pro 5 16AFR10
BIOS Update for Windows 11 (64-bit) - Legion Go 8ASP2
BIOS Update for Windows 11 (64-bit) - Legion 5 15AKP10
BIOS Update for Windows 10 (64-bit), Windows 11 (64-bit) - IdeaPad Slim 5 14AKP10, IdeaPad Slim 5 16AKP10
BIOS Update for Windows 11 (64-bit) - IdeaPad Pro 5 16ASP10, IdeaPad Pro 5 16AKP10
BIOS Update for Windows 11 (64-bit) - IdeaPad Pro 5 14AKP10, IdeaPad Pro 5 14ASP10
BIOS Update for Windows 11 (64-bit) - IdeaPad 5 2-in-1 14AKP10, IdeaPad 5 2-in-1 16AKP10
Flash BIOS Update (For AMD Krackan Point) - ThinkCentre Neo 55q Gen 6 (Type 13GT, 13GU, 13GV, 13GW)
BIOS for Windows 11 (64-bit) - LOQ Tower 26ADR10
BIOS for Windows 11 (64-bit) - Legion T5 30AGB10
Flash BIOS Update - ThinkCentre Neo 55s Gen 6, IdeaCentre Tower 08AKP10
BIOS Update (Utility & Bootable CD) for Windows 11 (64-bit) - ThinkPad X13 Gen 6 (Type 21RM, 21RN)
Flash BIOS update for Windows 10 IOT, 11 IOT - ThinkStation P8
Flash BIOS Update - ThinkStation P8
Citrix XenServer
Ubuntu
amd64-microcode (Ubuntu package)
linux (Ubuntu package)
linux-fips (Ubuntu package)
linux-hwe-6.8 (Ubuntu package)
linux-ibm (Ubuntu package)
linux-oracle-6.8 (Ubuntu package)
linux-nvidia (Ubuntu package)
linux-aws-6.8 (Ubuntu package)
linux-aws (Ubuntu package)
linux-raspi (Ubuntu package)
linux-azure-fde (Ubuntu package)
linux-azure-fde-6.8 (Ubuntu package)
linux-azure (Ubuntu package)
linux-azure-fips (Ubuntu package)
linux-gcp-fips (Ubuntu package)
linux-gcp-6.17 (Ubuntu package)
linux-realtime-6.17 (Ubuntu package)
linux-oem-6.17 (Ubuntu package)

How to mitigate CVE-2025-62626

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

Flash BIOS update for Windows 10 IOT, 11 IOT - ThinkStation P8 - update to S0GKT49A
Flash BIOS Update - ThinkStation P8 - update to S0GKT49A
amd64-microcode (Ubuntu package) - addressed in versions 3.20251202.1ubuntu0.24.04.1, 3.20251202.1ubuntu0.25.10.1
linux (Ubuntu package) - addressed in versions 6.8.0-136.136, 6.8.0-1046.50, 6.8.0-1059.67, 6.8.0-1064.72, 6.8.0-1064.72~22.04.1, 6.8.1-1056.57, 6.8.1-1056.57~22.04.2, 6.17.0-19.19, 6.17.0-19.19~24.04.2, 6.17.0-1009.9, 6.17.0-1009.9~24.04.1, 6.17.0-1009.9~24.04.2
linux-fips (Ubuntu package) - addressed in versions 6.8.0-136.136+fips2, 6.8.0-136.136.2, 6.8.0-136.136.2~22.04.1, 6.8.0-1058.61
linux-hwe-6.8 (Ubuntu package) - update to 6.8.0-136.136~22.04.1
linux-ibm (Ubuntu package) - addressed in versions 6.8.0-1030.31, 6.8.0-1033.34, 6.8.0-1061.62, 6.8.0-1061.62~22.04.1
linux-oracle-6.8 (Ubuntu package) - update to 6.8.0-1058.61~22.04.1
linux-nvidia (Ubuntu package) - addressed in versions 6.8.0-1059.62, 6.8.0-1059.62.1, 6.8.0-1059.62~22.04.1
linux-aws-6.8 (Ubuntu package) - addressed in versions 6.8.0-1061.64+fips1, 6.8.0-1061.64~22.04.1
linux-aws (Ubuntu package) - update to 6.8.0-1061.64+1
linux-raspi (Ubuntu package) - addressed in versions 6.8.0-1061.65, 6.8.0-2050.52, 6.17.0-1010.10
linux-azure-fde (Ubuntu package) - update to 6.8.0-1062.69
linux-azure-fde-6.8 (Ubuntu package) - update to 6.8.0-1062.69~22.04.1
linux-azure (Ubuntu package) - addressed in versions 6.8.0-1063.71, 6.8.0-1063.71~22.04.1, 6.17.0-1010.10, 6.17.0-1010.10~24.04.1
linux-azure-fips (Ubuntu package) - update to 6.8.0-1063.71+fips2
linux-gcp-fips (Ubuntu package) - update to 6.8.0-1064.72+fips1
linux-gcp-6.17 (Ubuntu package) - addressed in versions 6.17.0-1008.9, 6.17.0-1009.9~24.04.3
linux-realtime-6.17 (Ubuntu package) - update to 6.17.0-1008.9~24.04.1
linux-oem-6.17 (Ubuntu package) - update to 6.17.0-1017.17

External References

Related Security Bulletins