Analyzed
Published: 01 May 2025, 12:55
Last modified:11 May 2026, 21:14

Vulnerability Summary

Overall Risk (default)
low
22/100
CVSS Score
5.5 MEDIUM
v3.1 (nvd)
EPSS Score
0.07% LOW
0% probability +0.05%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 May 2025, 12:55
Published
Vulnerability first disclosed
11 May 2026, 21:14
Last Modified
Vulnerability information updated

Description

In the Linux kernel, the following vulnerability has been resolved: x86/cpu: Avoid running off the end of an AMD erratum table The NULL array terminator at the end of erratum_1386_microcode was removed during the switch from x86_cpu_desc to x86_cpu_id. This causes readers to run off the end of the array. Replace the NULL.

CVSS Metrics

  • v3.1MEDIUMScore: 5.5CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.07% Percentile: 22%

Affected Systems

  • linuxlinux

    ≥ f3f3251526739bb975b97f840c56b3054dba8638, < 1b518f73f1b6f59e083ec33dea22d9a1a275a970 | ≥ f3f3251526739bb975b97f840c56b3054dba8638, < f0df00ebc57f803603f2a2e0df197e51f06fbe90 | 6.14

  • linuxlinux_kernel

    ≥ 6.14, < 6.14.3 | 6.15:rc1

References (2)