Database/Firmware, BMC & network fabric
Intel Xeon 6 E-core with TDX or SGX: Improper restriction of software interfaces to hardware features on Xeon 6 E-core
CVSS 6.1CVE-2024-48869Firmware, BMC & network fabriccurated
Impact
Improper restriction of software interfaces to hardware features on Xeon 6 E-core parts when TDX or SGX is in use. Reaches both confidential-compute technologies on the same silicon, so a single platform update covers both boundaries.
Who can reach it
Local access on an affected Xeon 6 platform with TDX or SGX enabled.
What to do
OEM platform firmware/BIOS update plus TCB recovery for whichever technology you use. Drain, reboot, re-attest.
References
Related entries
- Intel Ethernet E810 Series and Ethernet 700 Series firmware: Out-of-bounds write in firmware across both the E810 lineCVE-2022-36382 · Intel Ethernet E810 Series and Ethernet 700 Series firmwareMedium
- Intel processors with SGX (shared resource isolation): Improper isolation of shared microarchitectural resources lets aCVE-2022-38090 · Intel processors with SGX (shared resource isolation)Medium
- Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit): The dynamic-counter netlink setter bounded itsCVE-2022-49199 · Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit)Medium
- AMD SEV-SNP firmware, guest teardown / UMC key seed handling: TENANT HANDOFF FAILURECVE-2023-31355 · AMD SEV-SNP firmware, guest teardown / UMC key seed handlingMedium
- AMI MegaRAC SPx (IPMI handler): Arbitrary file upload and download through the BMC's IPMI handlerCVE-2023-34342 · AMI MegaRAC SPx (IPMI handler)Medium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-47855 · Intel TDX moduleMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.