Database/Firmware, BMC & network fabric
Intel TDX SEAM loader (Seamldr): Sensitive information is not cleared before a resource is reused in the SEAM loader
Impact
Sensitive information is not cleared before a resource is reused in the SEAM loader - the component that loads and measures the TDX module itself. Anything wrong at the SEAM loader layer is below the TDX module in the trust stack, so it undermines the measurement every TD attestation ultimately chains to.
Who can reach it
Privileged host user.
What to do
Update the TDX SEAM loader (Seamldr) to 1.5.02.00 or later alongside the TDX module. Loaded at boot, so drain all trust domains and reboot the node. Re-attest afterwards; the SEAM loader version feeds the attestation chain. No OEM BIOS dependency for the loader itself.
References
Related entries
- AMD SEV-SNP firmware - input validation: Improper input validation in SEV-SNP lets a malicious hypervisor read orCVE-2024-21978 · AMD SEV-SNP firmware - input validationMedium
- AMD Power Management Firmware (PMFW) - guest VM input validation causing GPU reset: Improper input validation in AMD'sCVE-2024-36346 · AMD Power Management Firmware (PMFW) - guest VM input validation causing GPU resetMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2024-39283 · Intel TDX moduleMedium
- GRUB2 (BFS filesystem parser): Integer overflow producing a heap out-of-bounds read in the BeFS parserCVE-2024-45779 · GRUB2 (BFS filesystem parser)Medium
- AMD SEV-SNP - RMP write access during SNP initialization: There is a window during SEV-SNP initialization in which anCVE-2025-0033 · AMD SEV-SNP - RMP write access during SNP initializationMedium
- Intel CSME / SPS firmware (timing side channel): An observable timing discrepancy in CSME/SPS firmware allowsCVE-2025-20067 · Intel CSME / SPS firmware (timing side channel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.