Database/Firmware, BMC & network fabric
Intel TDX firmware: Improper synchronisation in TDX firmware, exploitable by a privileged host user to escalate
Impact
Improper synchronisation in TDX firmware, exploitable by a privileged host user to escalate. Race conditions in the module are hard to trigger but sit on the tenant boundary.
Who can reach it
Privileged host user, requires winning a race.
What to do
Update the Intel TDX module. The TDX module is loaded by the SEAM loader at boot, so the practical rollout is: stage the new module, drain every trust domain off the node, and reboot. It is not a live-patchable component and running TDs cannot be migrated through it. After the update, every TD must re-attest because the TDX module SVN is part of the attestation report - so anything that pinned the old measurement will fail until you update your attestation policy too. No OEM BIOS release needed for the module itself, which makes this materially faster than a platform firmware update.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.