Description
Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Published: 2026-08-11
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Hardware logic in certain 3rd Generation Intel Xeon Scalable processors contains race conditions exploitable from Ring 3; unprivileged software running locally by a user with system privileges can, after a high‑complexity attack, trigger a denial of service. The flaw is classified as CWE‑1298 and affects only availability, with confidentiality and integrity remaining unaffected.

Affected Systems

Any system that incorporates 3rd Generation Intel Xeon Scalable processors is potentially vulnerable. Specific CPU model or microcode revisions are not listed, so all current variants of this processor family deployed in production may be at risk.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog. The attack is local, requiring an authenticated user to run malicious code that triggers the race condition; no additional user interaction or external network access is necessary. Successful exploitation would abruptly terminate or stall services depending on the affected CPU, leading to significant denial of availability for the vulnerable host.

Generated by OpenCVE AI on August 13, 2026 at 02:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Intel microcode or firmware updates that patch the race condition when they become available.
  • Enable system monitoring for abnormal CPU stalls, forced thread context switches, or recurrent service crashes, and set alerts to notify the security team.
  • Restrict installation or execution of untrusted local software at Ring 3 level, and where possible, isolate workloads using virtual machines or containers to contain the effect of a potential denial of service.

Generated by OpenCVE AI on August 13, 2026 at 02:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel 3rd Gen Intel Xeon Scalable Processors
Vendors & Products Intel
Intel 3rd Gen Intel Xeon Scalable Processors

Thu, 13 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title Denial of Service via Ring 3 Race Condition in 3rd Gen Intel Xeon Scalable Processors

Wed, 12 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
Weaknesses CWE-1298
References
Metrics cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:H'}


Subscriptions

Intel 3rd Gen Intel Xeon Scalable Processors
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T15:52:22.553Z

Reserved: 2025-12-18T04:00:20.416Z

Link: CVE-2026-20707

cve-icon Vulnrichment

Updated: 2026-08-12T15:52:13.571Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:49.353

Modified: 2026-08-12T20:54:11.500

Link: CVE-2026-20707

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T11:23:35Z

Weaknesses
  • CWE-1298

    Hardware Logic Contains Race Conditions