Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
High

Privilege Escalation via CPU Opcode Cache Corruption on AMD Zen 2

IdentifiersCVE-2025-54518CWE-668

CVE-2025-54518 is a hardware/microarchitectural vulnerability affecting AMD Family 17h processors based on the Zen 2 microarchitecture. The issue is described by AMD and Xen as improper isolation of shared resources within the CPU operation/opcode cache, which can allow instructions to be corrupted or executed at a higher privilege level than intended. In Xen’s assessment, this can permit code running at one privilege level to influence instructions executed at another privilege level. In virtualized environments, Xen states that all Xen versions are affected when running on vulnerable Zen 2 CPUs. The issue is referred to in Xen Security Advisory XSA-490 as “x86: CPU Opcode Cache corruption.”

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation can result in privilege escalation across protection boundaries. Reported impacts include escalation from userspace to kernel on affected systems and, in virtualized deployments, escalation from a guest VM to the Xen host/hypervisor. More generally, the flaw undermines privilege separation enforced by the CPU by allowing instruction corruption or higher-privilege execution, which could lead to full system compromise of the affected host or hypervisor context.

Mitigation

If you can’t patch tonight, do this now.

According to Xen Security Advisory XSA-490, there are no mitigations available short of applying the provided fixes. Where direct patching is not under the customer’s control, such as cloud or hosted EPYC 7002 environments, mitigation depends on the infrastructure provider deploying the relevant firmware/software updates.

Remediation

Patch, then assume compromise.

Apply vendor-provided fixes for affected environments. Xen states that remediation requires applying the relevant XSA-490 patches: xsa490.patch for xen-unstable, xsa490-4.21.patch for Xen 4.21.x through 4.18.x, and xsa490-4.17-1.patch plus xsa490-4.17-2.patch for Xen 4.17.x. Xen advises downstreams to update to the tip of the relevant stable branch before applying patches because they may not apply cleanly to release tarballs. The content also indicates that AMD has published bulletin AMD-SB-7052 and that firmware/microcode updates may be part of the remediation path, with EPYC 7002 and hosted/cloud deployments potentially requiring updates from OEMs or service providers.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

EXPOSURE SURFACE

Affected products & vendors

Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.

VendorProductType
Advanced Micro DevicesZen 2hardware

Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity10

Community discussion across Reddit, Mastodon, and other social sources.