CVE-2025-65264: Cpuid CPU-Z

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

The kernel driver of CPUID CPU-Z v2.17 and earlier does not validate user-supplied values passed via its IOCTL interface, allowing an attacker to access sensitive information via a crafted request.

Affected products

  • Cpuid CPU-Z: up to and including 2.17

Published 2026-01-27. Last modified 2026-06-17.