Database/Firmware, BMC & network fabric
Intel TDX module firmware: Missing check for an exceptional condition in the TDX module allows a privileged user
Impact
Missing check for an exceptional condition in the TDX module allows a privileged user to reach information disclosure. Scored very low, but it is inside the TDX TCB, so it still triggers a module SVN bump and therefore a re-attestation cycle.
Who can reach it
Privileged host user.
What to do
Update the Intel TDX module. The TDX module is loaded by the SEAM loader at boot, so the practical rollout is: stage the new module, drain every trust domain off the node, and reboot. It is not a live-patchable component and running TDs cannot be migrated through it. After the update, every TD must re-attest because the TDX module SVN is part of the attestation report - so anything that pinned the old measurement will fail until you update your attestation policy too. No OEM BIOS release needed for the module itself, which makes this materially faster than a platform firmware update.
References
Related entries
- AMI MegaRAC SPx (embedded lighttpd web server): Use-after-free in the lighttpd request parser embedded in MegaRAC SPxCVE-2018-25103 · AMI MegaRAC SPx (embedded lighttpd web server)Low
- Intel TDX firmware: Improper synchronisation in TDX firmware, exploitable by a privileged host user to escalateCVE-2025-22853 · Intel TDX firmwareLow
- Arista EOS: brief windows where 802.1X supplicant traffic passes without ACL enforcementCVE-2026-75943 · Arista EOS (802.1X dot1x ACL enforcement timing)Low
- Intel TDX firmware: Improper buffer restrictions in TDX firmware reachable by a privileged host user for privilegeCVE-2025-21096 · Intel TDX firmwareLow
- AMD SEV-SNP - selective DMA write drops on host-induced faults: By inducing faults, a high-privileged local attackerCVE-2025-0029 · AMD SEV-SNP - selective DMA write drops on host-induced faultsLow
- AMD SEV firmware - missing checks around RMP initialization (AMD-SB-3023): Missing checks around RMP initializationCVE-2025-48509 · AMD SEV firmware - missing checks around RMP initialization (AMD-SB-3023)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.