Critical AMD and Kernel Flaws Expose Cloud Linux Systems to Privilege Escalation
Multiple high-severity vulnerabilities in AMD processors and the Linux kernel impact cloud environments. Attackers can exploit these flaws to access sensitive data and escalate privileges.
TL;DR
- AMD processor flaws allow local attackers to leak sensitive data via speculative execution and cache isolation bypasses.
- Linux kernel vulnerabilities affect multiple architectures and subsystems, including ARM64, x86, and cryptographic APIs.
- New CVEs include CVE-2025-54505, CVE-2025-54518, and CVE-2025-62626 impacting Zen 2 and Zen 5 processors.
- Exploitation may lead to unauthorized data access, privilege escalation, and compromised system integrity.
- Ubuntu has released urgent updates across multiple cloud variants including Azure CVM, AWS, and FIPS kernels.
A series of critical vulnerabilities affecting both AMD processors and the Linux kernel pose significant risks to cloud-based systems. These flaws enable local attackers to extract sensitive information or elevate their privileges, threatening the confidentiality and integrity of affected systems.
The vulnerabilities span several AMD processor generations, particularly targeting speculative execution units and shared resource isolation mechanisms. Concurrently, flaws within the Linux kernel's handling of NTFS filesystems and various hardware abstraction layers increase the attack surface across diverse computing environments.
AMD Processor Vulnerabilities Enable Local Data Extraction
- CVE-2025-54505 affects some AMD processors where data in the floating-point divider unit is not cleared during speculative execution, allowing potential leakage of sensitive information.
- CVE-2025-54518 impacts AMD Zen 2 processors due to improper isolation of shared resources in the operation cache, which could allow corruption of higher-privilege instructions.
- CVE-2025-62626 targets AMD Zen 5 processors supporting RDSEED instruction, where insufficient entropy handling may result in predictable random values compromising confidentiality and integrity.
Widespread Linux Kernel Issues Across Architectures and Subsystems
- CVE-2023-45896 involves an out-of-bounds read in the NTFS file system implementation, enabling attackers to craft malicious images that expose kernel memory upon mounting.
- Multiple architectural flaws exist across ARM32, ARM64, MIPS, PowerPC, RISC-V, S390, and x86 platforms requiring coordinated patches.
- Core subsystems such as block layer, cryptographic API, drivers core, network components, and device interfaces contain exploitable weaknesses addressed in recent updates.
- Cloud-specific kernel variants like Azure CVM, Azure FIPS, and AWS distributions are among those patched to mitigate these widespread issues.
Sources
- USN-8610-1: Linux kernel (Azure CVM) vulnerabilities
- USN-8575-3: Linux kernel vulnerabilities
- USN-8609-1: Linux kernel (Azure CVM) vulnerabilities
- USN-8608-1: Linux kernel (Azure FIPS) vulnerabilities
- USN-8607-1: Linux kernel (Azure CVM) vulnerabilities
- USN-8606-1: Linux kernel (Azure) vulnerabilities
- USN-8595-2: Linux kernel (AWS) vulnerabilities
- USN-8605-1: Linux kernel (Azure CVM) vulnerabilities
- USN-8604-1: Linux kernel (Azure) vulnerabilities
- USN-8603-1: Linux kernel (Azure) vulnerabilities
Sources
- USN-8610-1: Linux kernel (Azure CVM) vulnerabilities
- USN-8575-3: Linux kernel vulnerabilities
- USN-8609-1: Linux kernel (Azure CVM) vulnerabilities
- USN-8608-1: Linux kernel (Azure FIPS) vulnerabilities
- USN-8607-1: Linux kernel (Azure CVM) vulnerabilities
- USN-8606-1: Linux kernel (Azure) vulnerabilities
- USN-8595-2: Linux kernel (AWS) vulnerabilities
- USN-8605-1: Linux kernel (Azure CVM) vulnerabilities
- USN-8604-1: Linux kernel (Azure) vulnerabilities
- USN-8603-1: Linux kernel (Azure) vulnerabilities
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.