CVE detail
CVE-2025-54518
Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resulting in privilege escalation.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 20.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-54518.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMay 15, 2026, 5:16 AM - https://bugzilla.redhat.com/show_bug.cgi?id=2477784bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMay 15, 2026, 5:16 AM - https://access.redhat.com/security/cve/CVE-2025-54518access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comMay 15, 2026, 5:16 AM - http://xenbits.xen.org/xsa/advisory-490.htmlxenbits.xen.org
No excerpt available.
Vendor Advisoryxenbits.xen.orgMay 15, 2026, 5:16 AM - http://www.openwall.com/lists/oss-security/2026/05/12/15www.openwall.com
No excerpt available.
Exploitwww.openwall.comMay 15, 2026, 5:16 AM No excerpt available.
Vendor Advisorywww.amd.comMay 15, 2026, 5:16 AM- The May 2026 Security Update ReviewZero Day Initiative
take a closer look at some of the more interesting updates for this month, starting with a nasty-looking bug in DNS: - CVE-2026-41096 - Windows DNS Client Remote Code Execution Vulnerability This patch fixes a heap-based buffer overflow in the DNS Client triggered by a malicious DNS response. No authentication or user interaction needed, and since the
vendorwww.thezdi.comMay 12, 2026, 6:38 PM This vulnerability was found and addressed by AMD. We are documenting it in the Security Update Guide to encourage customers to install the May 2026 version of Windows as soon as possible. The vulnerability assigned to this CVE is in certain processor models offered by AMD. The mitigation for this vulnerability requires a Windows update. This CVE is being documented in the Security Update Guide to announce that the latest builds of Windows enable the mitigation and provide protection against the
vendormsrc.microsoft.comMay 12, 2026, 2:00 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16560CVSS 5.3 · Medium
A heap-buffer-overflow flaw was found in Directory Server (389-ds-base). When a DN contains a legacy-quoted value, the server won't close the heap allocation allowing another call…
- CVE-2026-50502CVSS 8.0 · High
Insufficient granularity of access control in Windows Event Logging Service allows an authorized attacker to execute code over a network.
- CVE-2026-50405CVSS 7.8 · High
Insufficient granularity of access control in Windows Filtering Platform (WFP) allows an authorized attacker to elevate privileges locally.
- CVE-2026-56155CVSS 7.8 · High
Insufficient granularity of access control in Active Directory Federation Services (AD FS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-55006CVSS 7.8 · High
Insufficient granularity of access control in Microsoft Exchange Server allows an authorized attacker to elevate privileges locally.
- CVE-2026-49170CVSS 7.8 · High
Insufficient granularity of access control in Windows StateRepository API allows an authorized attacker to elevate privileges locally.