GPU VulnDB

Database/Firmware, BMC & network fabric

Intel TDX SEAM loader (Seamldr): Sensitive information is not cleared before a resource is reused in the SEAM loader

CVE-2024-21850Firmware, BMC & network fabriccurated

Impact

Sensitive information is not cleared before a resource is reused in the SEAM loader - the component that loads and measures the TDX module itself. Anything wrong at the SEAM loader layer is below the TDX module in the trust stack, so it undermines the measurement every TD attestation ultimately chains to.

Who can reach it

Privileged host user.

What to do

Update the TDX SEAM loader (Seamldr) to 1.5.02.00 or later alongside the TDX module. Loaded at boot, so drain all trust domains and reboot the node. Re-attest afterwards; the SEAM loader version feeds the attestation chain. No OEM BIOS dependency for the loader itself.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.