Database/Firmware, BMC & network fabric
Intel TDX module: An out-of-bounds read in the TDX module reachable by an authenticated user, leaking information
Impact
An out-of-bounds read in the TDX module reachable by an authenticated user, leaking information across the TDX boundary. Read primitives inside the module are the ones to watch: they are the shape that leaks other trust domains' state.
Who can reach it
An authenticated user on the host.
What to do
Update the Intel TDX module. The TDX module is loaded by the SEAM loader at boot, so the practical rollout is: stage the new module, drain every trust domain off the node, and reboot. It is not a live-patchable component and running TDs cannot be migrated through it. After the update, every TD must re-attest because the TDX module SVN is part of the attestation report - so anything that pinned the old measurement will fail until you update your attestation policy too. No OEM BIOS release needed for the module itself, which makes this materially faster than a platform firmware update.
References
Related entries
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2025-20044 · Intel TDX moduleMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-45745 · Intel TDX moduleHigh
- Intel TDX module: Insufficient control-flow management in the TDX module lets a privileged host user deny serviceCVE-2024-21801 · Intel TDX moduleHigh
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-47855 · Intel TDX moduleMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2024-39283 · Intel TDX moduleMedium
- Intel Atom processors (shared predictor transient execution): Shared microarchitectural predictor state influencesCVE-2024-43420 · Intel Atom processors (shared predictor transient execution)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.