#FPDSS
TREVEX: Black-Box CPU Fuzzing Finds FP-DSS, New FPVI Variants, and Zero-at-ret
TREVEX is a post-silicon black-box CPU fuzzer from CISPA designed to discover data-flow transient execution vulnerabilities without needing RTL access, an ISA emulator, or a leakage contract. The framework runs across 20 microarchitectures from Intel, AMD, and Zhaoxin and uncovers a new TEA — Floating Point Divider State Sampling (FP-DSS, CVE-2025-54505) — on AMD Zen and Zen+, a new FPVI variant on AMD that does not need denormal inputs, three instances of Zero-at-ret on Intel, and FPVI on Zhaoxin. The authors weaponise FP-DSS from native code, the Linux kernel, and a Chrome JavaScript exploit. {"_yoast_wpseo_title": "TREVEX: Black-Box CPU Fuzzer Finds FP-DSS (CVE-2025-54505)", "_yoast_wpseo_metadesc": "TREVEX black-box CPU fuzzer (CISPA, S&P 2026) finds FP-DSS (CVE-2025-54505), new FPVI variants, and Zero-at-ret across 20 Intel, AMD, Zhaoxin microarchitectures.", "rank_math_title": "TREVEX: Black-Box CPU Fuzzer Finds FP-DSS (CVE-2025-54505)", "rank_math_description": "TREVEX black-box CPU fuzzer (CISPA, S&P 2026) finds FP-DSS (CVE-2025-54505), new FPVI variants, and Zero-at-ret across 20 Intel, AMD, Zhaoxin microarchitectures."}
core-jmp.org
May 23, 2026 at 6:46 PM
🚨 EUVD-2026-25521
📊 n/a
🏢 Linux

📝 In the Linux kernel, the following vulnerability has been resolved:

x86/CPU: Fix FPDSS on Zen1

Zen1's hardware divider can leave, under certain circumstances...

🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-25521

#cybersecurity #infosec #cve #euvd
April 24, 2026 at 4:08 PM