Database/Firmware, BMC & network fabric
Linux kernel SEV-ES #VC handler - MMIO access checking: Incorrect access checking in the SEV-ES #VC handler and
Impact
Incorrect access checking in the SEV-ES #VC handler and instruction emulation lets a local user with userspace access to MMIO registers escalate. Inside a confidential VM, a merely local user reaches privileged guest state through the exception handler that SEV-ES uses to virtualise MMIO - so the confidential VM's own internal privilege boundary breaks, not just the host/guest one.
Who can reach it
Local, from userspace inside an SEV-ES guest that has userspace-accessible MMIO. Affects Linux before 6.5.9.
What to do
Fixed in the Linux kernel. Take the distro kernel update (RHEL/Rocky, Ubuntu, SLES) and reboot the host - no firmware, VBIOS or AGESA step. On a GPU fleet this is a cordon, drain and rolling reboot; plan it as normal kernel maintenance. The fix belongs in the **guest** kernel, so update your confidential-VM images (or publish a minimum guest kernel to tenants) rather than assuming host patching covers it.
References
Related entries
- Dell iDRAC Service Module (incorrect default permissions): Weak default folder permissions let an unprivileged localCVE-2024-22428 · Dell iDRAC Service Module (incorrect default permissions)High
- Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620CVE-2024-47975 · Solidigm DC SSDs with TCG Opal (DC P4510/P4511/P4610 Opal, D5-P4320/P4326 Opal, D5-P5316 Opal, D7-P5510/P5520/P5620…High
- Intel Xeon 6 with TDX: overlapping protected memory ranges in SMM allow privilege escalationCVE-2025-31936 · Intel Xeon 6 processors with Intel TDX (protected memory range overlap handling in SMM)High
- EDK II (SMM environment, Machine Check Exception handling): Machine Check Exceptions are enabled before SMM installsCVE-2025-3770 · EDK II (SMM environment, Machine Check Exception handling)High
- Lenovo XClarity Orchestrator: microservices accept invalid TLS certificates, exposing management trafficCVE-2026-16792 · Lenovo XClarity Orchestrator 2.2.0 (microservice TLS certificate validation)High
- Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436: Improper authenticationCVE-2026-20885 · Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.