AMD CPUs Floating Point Divider Transient Execution Vulnerability Allowing Data Leakage

Vulnerability

A transient execution vulnerability has been identified in multiple generations of AMD CPUs. This vulnerability may allow a local user-privileged attacker to leak sensitive data through the floating-point divisor unit, potentially leading to a loss of confidentiality. The issue affects systems with Simultaneous Multithreading (SMT) enabled, as well as those without it.

Impact

Exploitation of this vulnerability could result in unauthorized data leakage, compromising sensitive information.

Remediation

For affected Zen and Zen+ processors, this vulnerability may be mitigated at the operating system level by setting bit 9 of MSR C001_1028 to 1. AMD is collaborating with upstream Linux maintainers to facilitate the integration of this mitigation. Users are advised to contact their operating system vendor regarding available mitigations.

Added: Apr 27, 2026, 4:35 PM
Updated: Apr 27, 2026, 4:35 PM

Vulnerability Rating

Custom Algorithm
spread
7.8
impact
0.2
exploitability
3.3
remediation
7.9
relevance
6.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.