Junglewise Threat Intelligence

CVE-2026-20917: Intel Processors Load Value Injection information disclosure

CVE-2026-20917 · Severity: info · CVSS 4 · Published 2026-08-11

Vendors: Intel.

Executive brief

Intel processors contain a vulnerability in their transient execution hardware that can leak sensitive kernel and hypervisor data to unprivileged attackers. An adversary with high-complexity attack conditions and system-level privileges could exploit this to read protected memory regions, potentially compromising cryptographic keys, passwords, and other confidential data stored in kernel or hypervisor memory.

Technical details

This vulnerability exploits incorrect data forwarding during transient execution in Intel processors' Ring 0 execution context (kernel and hypervisor modes). The attack class falls under Load Value Injection (LVI), a transient execution side-channel vulnerability. Exploitation requires local access and high attack complexity combined with privileged user context, but does not require special knowledge or user interaction. An attacker can read arbitrary kernel or hypervisor memory by manipulating CPU execution paths during speculative operations. Intel has released microcode updates to mitigate this issue through system manufacturers.

Affected products

  • Intel Core Processors (10th Generation) 10th Generation
  • Intel Xeon Scalable Processors (3rd Generation) 3rd Generation
  • Intel Xeon D Processor
  • Intel Xeon E-2300 Series
  • Intel Core Processors (11th Generation) 11th Generation

Timeline

  • 2026-08-11: disclosed: Intel SA-01423 advisory published; microcode updates released

References