Database/Firmware, BMC & network fabric
Intel Xeon memory controller configuration (with SGX): MULTI-TENANT ISOLATION: Memory controller configuration
Impact
MULTI-TENANT ISOLATION: Memory controller configuration registers are left with permissions that let a privileged local user reach a privilege escalation on SGX-enabled Xeon platforms. Memory controller configuration is the layer that enforces where enclave memory lives, so getting it wrong is structurally worse than a normal ring-0 bug on a confidential-compute host.
Who can reach it
Privileged local access on the host.
What to do
Platform BIOS/firmware update from the OEM, plus TCB recovery and re-attestation. BIOS means a per-node drain, a reboot, and waiting on OEM packaging - budget quarters, not weeks, on server boards.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.