In the Linux kernel, the following vulnerability has been resolved:
x86/cpu: Avoid running off the end of an AMD erratum table
The NULL array terminator at the end of erratum_1386_microcode was removed during the switch from x86_cpu_desc to x86_cpu_id. This causes readers to run off the end of the array.
Replace the NULL.
CVSS Details
- CVSS 3.1 Base Score: 7.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 1, 2025 |
| Ubuntu | — | Upgrade linux-image-6.14.0-22-generic-64kUpgrade linux-image-6.14.0-1004-realtimeUpgrade linux-image-6.14.0-1007-raspiUpgrade linux-image-6.14.0-1007-azure-fdeUpgrade linux-image-6.14.0-1008-gcp-64kUpgrade linux-image-azure-fdeUpgrade linux-image-awsUpgrade linux-image-genericUpgrade linux-image-6.14.0-1007-oracle-64kUpgrade linux-image-6.14.0-1008-gcpUpgrade linux-image-oracleUpgrade linux-image-6.14.0-22-genericUpgrade linux-image-generic-64kUpgrade linux-image-aws-64kUpgrade linux-image-6.14.0-1007-awsUpgrade linux-image-raspiUpgrade linux-image-6.14.0-1007-azureUpgrade linux-image-6.14.0-1007-aws-64kUpgrade linux-image-oracle-64kUpgrade linux-image-azureUpgrade linux-image-gcpUpgrade linux-image-gcp-64kUpgrade linux-image-realtimeUpgrade linux-image-6.14.0-1007-oracle | Jun 26, 2025 | May 1, 2025 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub