Executive brief
Intel's 3rd Generation Xeon Scalable Processors, which are widely used in server environments to process enterprise workloads, contain a hardware race condition that can be exploited by unprivileged local users to cause system denial of service. An attacker with local access could trigger a crash or hang that disrupts server availability and business operations, though the attack requires high complexity and specialized knowledge.
Technical details
A hardware logic race condition exists in 3rd Gen Intel Xeon Scalable Processors that can be triggered within Ring 3 (unprivileged execution mode). The vulnerability requires local access, an authenticated user account, high attack complexity, and specialized internal knowledge to exploit. An unprivileged adversary can cause a denial of service by inducing the race condition, resulting in system unavailability. Intel has released microcode updates available through system manufacturer firmware updates and on the Intel Linux Processor Microcode Data Files public repository to mitigate this issue.
Affected products
- Intel 3rd Generation Xeon Scalable Processor Whitley generation (CPU ID 606A6)
- Intel Xeon Processor D Family Idaville (CPU ID 606C1)
Timeline
- 2026-08-11: disclosed