Database/Firmware, BMC & network fabric
Intel 3rd/4th Gen Xeon with SGX or TDX (protection mechanism failure): MULTI-TENANT ISOLATION: A protection mechanism
CVE-2023-22655Firmware, BMC & network fabriccurated
Impact
MULTI-TENANT ISOLATION: A protection mechanism in 3rd and 4th generation Xeon fails when SGX or TDX is in use, letting a privileged local user escalate. Affects the exact Xeon generations most AI datacenter hosts were built on between 2021 and 2024.
Who can reach it
Privileged local access on the host.
What to do
Microcode update plus TCB recovery. Late-loadable microcode, reboot, then re-attest enclaves and trust domains.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.