Impact
Hardware logic in certain 3rd Generation Intel Xeon Scalable processors contains race conditions exploitable from Ring 3; unprivileged software running locally by a user with system privileges can, after a high‑complexity attack, trigger a denial of service. The flaw is classified as CWE‑1298 and affects only availability, with confidentiality and integrity remaining unaffected.
Affected Systems
Any system that incorporates 3rd Generation Intel Xeon Scalable processors is potentially vulnerable. Specific CPU model or microcode revisions are not listed, so all current variants of this processor family deployed in production may be at risk.
Risk and Exploitability
The CVSS score of 6.8 indicates moderate severity, while the EPSS score of less than 1 % suggests a low probability of exploitation at present. The issue is not listed in the CISA KEV catalog. The attack is local, requiring an authenticated user to run malicious code that triggers the race condition; no additional user interaction or external network access is necessary. Successful exploitation would abruptly terminate or stall services depending on the affected CPU, leading to significant denial of availability for the vulnerable host.
OpenCVE Enrichment