CVE-2026-20707

EUVD-2026-56472
Hardware logic contains race conditions for some 3rd Gen Intel(R) Xeon(R) Scalable Processors within Ring 3: unprivileged software may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are not present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
UNKNOWN
---
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 0.1%
Debian logo
Debian Releases
Debian Product
Codename
intel-microcode
bookworm
postponed
bookworm/non-free-firmware
vulnerable
bookworm/non-free-firmware (security)
vulnerable
forky/non-free-firmware
vulnerable
sid/non-free-firmware
vulnerable
trixie
postponed
trixie/non-free-firmware
vulnerable
trixie/non-free-firmware (security)
vulnerable
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
intel-microcode
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
trusty
needs-triage
xenial
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
microcode_ctl
Amazon Linux 2
2:2.1-47.amzn2.4.28
fixed
Amazon Linux 2023
2:2.1-53.amzn2023.0.16
fixed
microcode_ctl-debuginfo
Amazon Linux 2
2:2.1-47.amzn2.4.28
fixed