Upstream information

CVE-2025-62626 at MITRE

Description

Improper handling of insufficient entropy in the AMD CPUs could allow a local attacker to influence the values returned by the RDSEED instruction, potentially resulting in the consumption of insufficiently random values.

SUSE information

Overall state of this security issue: Resolved

This issue is currently rated as having important severity.

CVSS v4 Scores
CVSS detail CNA (AMD)
Base Score 7.2
Vector CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Attack Vector Local
Attack Complexity Low
Attack Requirements Present
Privileges Required Low
User Interaction None
Vulnerable System Confidentiality Impact High
Vulnerable System Integrity Impact High
Vulnerable System Availability Impact None
Subsequent System Confidentiality Impact None
Subsequent System Integrity Impact None
Subsequent System Availability Impact None
CVSSv4 Version 4.0
No SUSE Bugzilla entries cross referenced.

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Liberty Linux 7 LTSS
  • iwl100-firmware >= 39.31.5.1-999.44.1.el7
  • iwl1000-firmware >= 39.31.5.1-999.44.1.el7
  • iwl105-firmware >= 18.168.6.1-999.44.1.el7
  • iwl135-firmware >= 18.168.6.1-999.44.1.el7
  • iwl2000-firmware >= 18.168.6.1-999.44.1.el7
  • iwl2030-firmware >= 18.168.6.1-999.44.1.el7
  • iwl3160-firmware >= 22.0.7.0-999.44.1.el7
  • iwl3945-firmware >= 15.32.2.9-999.44.1.el7
  • iwl4965-firmware >= 228.61.2.24-999.44.1.el7
  • iwl5000-firmware >= 8.83.5.1_1-999.44.1.el7
  • iwl5150-firmware >= 8.24.2.2-999.44.1.el7
  • iwl6000-firmware >= 9.221.4.1-999.44.1.el7
  • iwl6000g2a-firmware >= 17.168.5.3-999.44.1.el7
  • iwl6000g2b-firmware >= 17.168.5.2-999.44.1.el7
  • iwl6050-firmware >= 41.28.5.1-999.44.1.el7
  • iwl7260-firmware >= 22.0.7.0-999.44.1.el7
  • iwlax2xx-firmware >= 20251030-999.44.1.el7
  • linux-firmware >= 20251030-999.44.1.gite9292517.el7
Patchnames:
ESSA-2025:3472


SUSE Timeline for this CVE

CVE page created: Fri Nov 21 22:00:26 2025
CVE page last modified: Mon Nov 24 22:26:11 2025