Database/Firmware, BMC & network fabric
Intel Xeon processor firmware (SGX enabled): MULTI-TENANT ISOLATION: Improper buffer restrictions in Xeon firmware
CVE-2025-20053Firmware, BMC & network fabriccurated
Impact
MULTI-TENANT ISOLATION: Improper buffer restrictions in Xeon firmware on SGX-enabled parts, giving a privileged local user an escalation path. Firmware-level, so it lands underneath anything the OS can defend.
Who can reach it
Privileged local access on the host.
What to do
Platform firmware/BIOS update from the OEM plus SGX TCB recovery. Full drain and reboot per node; OEM release timing dominates the rollout.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.