Database/Control plane, storage & DevOps
AMD CPUs - attacker influence over RDSEED entropy: A local attacker can influence the values RDSEED returns, causing
Impact
A local attacker can influence the values RDSEED returns, causing consumers to draw insufficient entropy. Anything on the node that seeds a key, nonce or token from the hardware RNG - including confidential guests that deliberately chose the hardware source because they do not trust the host - gets attacker-influenced material. The failure is silent: the instruction reports success, and nothing downstream can tell the difference until someone else predicts the key.
Who can reach it
Local. The attacker influences entropy consumed by other software on the same machine, including guests.
What to do
Mitigated by AMD microcode plus, on most of these, a kernel-side change - and the durable delivery vehicle is the OEM SBIOS/AGESA package, which carries **one to six months of OEM lag** and needs a drained node and a full power cycle. The linux-firmware amd-ucode blobs get you the microcode sooner via initramfs early-load and a reboot, but AMD does not support late-loading microcode on a running EPYC host, so either way this is reboot-required, not a live patch. Also update guest and host kernels so the OS entropy pool does not lean solely on RDSEED. Any long-lived key generated on an affected host before patching should be rotated - the fix protects future output, not keys already derived.
References
Related entries
- Dell OpenManage Enterprise: unauthenticated SSRF reaches services on the management networkCVE-2026-54794 · Dell OpenManage Enterprise (web interface)High
- Dell OpenManage Enterprise: privileged user can inject OS commands and run code on the applianceCVE-2026-54796 · Dell OpenManage Enterprise (OS command handling)High
- Ivanti Endpoint Manager Mobile: Improper input validationCVE-2026-6973 · Ivanti Endpoint Manager MobileHigh
- Dell OpenManage Enterprise: improper privilege management lets a privileged account escalate furtherCVE-2026-70421 · Dell OpenManage Enterprise (privilege management)High
- Pandora FMS: blind SQL injection through the module parameter of the Grafana datasource endpointCVE-2026-75786 · Pandora FMS (Grafana datasource endpoint, module parameter)High
- MongoDB Server: use-after-free in query memory tracking crashes or corrupts the server processCVE-2026-82061 · MongoDB Server (query execution memory tracking)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.