Instruction
ERETU
Returns from a FRED event handler in ring 0 to ring 3, restoring the user context from the stack and swapping the GS base with IA32_KERNEL_GS_BASE.
- Extensions
- Forms
- 1 (1 Legacy)
- Data
- Intel XED v2026.08.23
ERETU is the way back to user mode when FRED is enabled. It expects RSP to point at the frame that FRED event delivery pushed, skips the error code, and restores RIP, CS, RFLAGS, RSP and SS from it, loading CS and SS for ring 3 based on IA32_STAR. It also swaps the GS base with IA32_KERNEL_GS_BASE, undoing the swap made on entry.
It works only at privilege level 0 with FRED enabled (#UD otherwise), and only at stack level 0 (#GP otherwise). With supervisor shadow stacks enabled it also checks the shadow-stack pointers. ERETS is the counterpart for events that happened in the kernel: it returns within ring 0 and leaves CS, SS and GS alone.
Forms
| Instruction | Encoding | Requires |
|---|---|---|
ERETU 64-bit mode only
ERETU | F3 0F 01 CA | FRED |
CPUID and processors
Each form belongs to an XED ISA set. A form can be used when the processor reports every CPUID bit of one of its ISA set's alternatives.
| ISA set | CPUID | Processors in XED |
|---|---|---|
FRED | FRED | Panther Lake, Nova Lake, Diamond Rapids |
More FRED instructions
Sources
- Intel XED v2026.08.23 (commit
0bcb6237345c): forms, encodings, ISA sets, CPUID bits and chip model. - Flexible Return and Event Delivery (FRED) Specification (346446-009)
- Intel 64 and IA-32 Architectures Software Developer's Manual, Volume 2 (325383-092, June 2026)
- Linux kernel documentation: Flexible Return and Event Delivery (FRED)
The tables are derived from Intel XED, Copyright Intel Corporation, licensed under the Apache License 2.0; x86-64.net converted and reformatted them. The text is our own.