Database/Control plane, storage & DevOps
AMD Zen 5 RDSEED (16-bit and 32-bit variants): On Zen 5, the 16-bit and 32-bit forms of RDSEED return zero far more
Impact
On Zen 5, the 16-bit and 32-bit forms of RDSEED return zero far more often than randomness allows, while still setting the carry flag to signal success. Any software that trusts RDSEED's success indicator - kernel entropy pools, TLS libraries, key generation inside confidential guests - silently consumes zeros as if they were seed material. This is a hardware entropy failure that announces nothing; you find it by auditing, not by observing symptoms.
Who can reach it
Not an attack in the usual sense - it is a silicon defect that any workload on affected Zen 5 parts hits passively. The exposure is that an attacker who knows a target derived keys from RDSEED on affected hardware can search a drastically reduced keyspace.
What to do
Fixed in the Linux kernel (x86/CPU/AMD) by masking off the broken RDSEED variants on affected Zen 5 parts, so the OS stops trusting them and falls back to working entropy sources. Take the distro kernel update and reboot the node; no firmware, microcode or BIOS step. Guest kernels need the same fix, so confidential-VM images must be updated too. Rotate any long-lived key material generated on affected Zen 5 hosts before the fix - the patch stops the bleeding but does not un-weaken existing keys.
References
Related entries
- Grafana: Auth Proxy cache key collision authenticates a low-privileged user as an administratorCVE-2026-14199 · Grafana Auth Proxy authentication (identity cache key built by concatenation)High
- GitLab EE: missing authorization lets a low-privileged member change restricted project settingsCVE-2026-16494 · GitLab EE (project update endpoint authorization)High
- Grafana: alert rule marked as a server-side expression bypasses datasource query authorizationCVE-2026-17183 · Grafana (alert rule server-side expression datasource authorization)High
- GitLab: unauthenticated GraphQL mutations executed via GET through multiplex query handlingCVE-2026-19650 · GitLab CE/EE (GraphQL multiplex query handling)High
- MinIO (server-side encryption / replication): An authenticated tenant can inject SSE metadata through replicationCVE-2026-34204 · MinIO (server-side encryption / replication)High
- MinIO (S3 Select): A crafted S3 Select CSV query makes MinIO allocate memory without bound until the process isCVE-2026-39414 · MinIO (S3 Select)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.