Database/Firmware, BMC & network fabric
Intel Xeon processors (SGX/TDX error injection): MULTI-TENANT ISOLATION: Unauthorised error injection against SGX
CVE-2022-41804Firmware, BMC & network fabriccurated
Impact
MULTI-TENANT ISOLATION: Unauthorised error injection against SGX or TDX on affected Xeon parts gives a privileged user an escalation. Fault injection against a TEE is the same family as Plundervolt: the host corrupts the protected computation until it gives up its secrets.
Who can reach it
Privileged local access on the host.
What to do
Microcode update - late-loadable at boot on most distributions, so this one does not wait on an OEM BIOS release - plus a TCB recovery and re-attestation. Reboot required.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.