Database/Firmware, BMC & network fabric
Intel TDX firmware: Improper synchronisation in TDX firmware, exploitable by a privileged host user to escalate
Impact
Improper synchronisation in TDX firmware, exploitable by a privileged host user to escalate. Race conditions in the module are hard to trigger but sit on the tenant boundary.
Who can reach it
Privileged host user, requires winning a race.
What to do
Update the Intel TDX module. The TDX module is loaded by the SEAM loader at boot, so the practical rollout is: stage the new module, drain every trust domain off the node, and reboot. It is not a live-patchable component and running TDs cannot be migrated through it. After the update, every TD must re-attest because the TDX module SVN is part of the attestation report - so anything that pinned the old measurement will fail until you update your attestation policy too. No OEM BIOS release needed for the module itself, which makes this materially faster than a platform firmware update.
References
Related entries
- Intel TDX firmware: Improper buffer restrictions in TDX firmware reachable by a privileged host user for privilegeCVE-2025-21096 · Intel TDX firmwareLow
- Arista EOS: brief windows where 802.1X supplicant traffic passes without ACL enforcementCVE-2026-75943 · Arista EOS (802.1X dot1x ACL enforcement timing)Low
- AMD SEV-SNP - selective DMA write drops on host-induced faults: By inducing faults, a high-privileged local attackerCVE-2025-0029 · AMD SEV-SNP - selective DMA write drops on host-induced faultsLow
- AMD SEV firmware - missing checks around RMP initialization (AMD-SB-3023): Missing checks around RMP initializationCVE-2025-48509 · AMD SEV firmware - missing checks around RMP initialization (AMD-SB-3023)Low
- AMD Secure Processor - incomplete cleanup exposing the Master Encryption Key (AMD-SB-3003): Incomplete cleanup in theCVE-2023-20518 · AMD Secure Processor - incomplete cleanup exposing the Master Encryption Key (AMD-SB-3003)Low
- Lenovo XClarity OneCLI: temp file handling lets a local user overwrite files when the tool runs elevatedCVE-2026-16791 · Lenovo XClarity Essentials OneCLI (Linux, 5.5.0 and below)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.