Intel and AMD Face WBINVD Security Flaw After x86 Entity Adds Skip Bits

Intel and AMD face a new security flaw as an x86 entity adds skip bits to the WBINVD instruction, exposing CPU caches to side- channel attacks.

Intel and AMD Face WBINVD Security Flaw After x86 Entity Adds Skip Bits

A mysterious x86 entity has registered new skip hint bits for the WBINVD instruction, forcing and to react to a security vulnerability they did not anticipate. This change matters because it exposes sensitive data in CPU caches during deep sleep or frequency scaling, creating a risk for side-channel attacks. Buyers and system administrators must now monitor for microcode updates and software workarounds to protect their hardware from these specific cache-based exploits.

New instruction bits bypass vendor controls and expose cache data

The WBINVD (Write Back and Invalidate Cache) instruction traditionally allows software to manage cache coherence, but the new registration bypasses standard vendor controls. The update introduces 4 public bits and 6 implementation-specific bits, allowing for instruction combinations up to 12 bytes long. This technical shift enables the skipping of L0i/L1i, L0d/L1d, and LLC invalidation operations, altering how processors handle cache state transitions.

Intel is currently collaborating with operating system vendors to develop software workarounds for this architectural change. AMD has already released microcode updates for its and EPYC processors to address the vulnerability. The identity of the entity registering these bits remains undetermined, though some speculation points to RosaicLabs, a startup rumored to have obtained design authorization for Intel processors.

Previous disclosures from this same entity included x86 opcodes and AMX implementation details in July 2025, establishing a pattern of third-party intervention in x86 instruction sets. We looked at Intel and AMD Survive 45 Years in our earlier Intel coverage while tracking these developments. The situation highlights the growing complexity of x86 security, where external entities can register instruction prefixes that impact major processor manufacturers.

Discussion

0 comments

Log in to join the thread with a thoughtful take, question, or correction.

Add to the discussion