Database/Firmware, BMC & network fabric
Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the box
Impact
The TDX module is the software that stands between the host/VMM and every confidential VM on the box; a privilege escalation inside it is a break of the boundary that separates a tenant's trust domain from the operator and from other TDs. Specific flaw: improper locking, letting a privileged host user escalate.
Who can reach it
A privileged user on the host - which in the TDX threat model is the adversary the whole design exists to exclude, so 'requires host privilege' is not a mitigating factor here.
What to do
Update the Intel TDX module. The TDX module is loaded by the SEAM loader at boot, so the practical rollout is: stage the new module, drain every trust domain off the node, and reboot. It is not a live-patchable component and running TDs cannot be migrated through it. After the update, every TD must re-attest because the TDX module SVN is part of the attestation report - so anything that pinned the old measurement will fail until you update your attestation policy too. No OEM BIOS release needed for the module itself, which makes this materially faster than a platform firmware update.
References
Related entries
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-45745 · Intel TDX moduleHigh
- Intel TDX module: Insufficient control-flow management in the TDX module lets a privileged host user deny serviceCVE-2024-21801 · Intel TDX moduleHigh
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-47855 · Intel TDX moduleMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2024-39283 · Intel TDX moduleMedium
- Intel TDX module: An out-of-bounds read in the TDX module reachable by an authenticated user, leaking informationCVE-2024-33607 · Intel TDX moduleMedium
- Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode)CVE-2018-12037 · Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode); Samsung T3 and T5 portable SSDs…Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.