Database/Firmware, BMC & network fabric
Intel Xeon 6 with TDX (protected memory range handling): Improper handling of overlap between protected memory ranges
CVSS 7.9CVE-2025-22889Firmware, BMC & network fabriccurated
Impact
Improper handling of overlap between protected memory ranges on Xeon 6 with TDX lets a privileged user escalate. Protected memory range enforcement is how TDX keeps one trust domain's pages away from the host and from other TDs, so overlap handling failing is the isolation primitive itself failing.
Who can reach it
Privileged host user on a Xeon 6 TDX platform.
What to do
OEM platform firmware/BIOS update, not just a TDX module update - which means waiting on your server vendor, a per-node drain and a reboot. Re-attest all trust domains after.
References
Related entries
- IBM Power Systems Firmware: BMC/FSP root can read and disrupt host processor state across all partitionsCVE-2026-17063 · IBM Power Systems Firmware (BMC/FSP-to-host interface, processor state)High
- TPM 2.0 reference code: leak lets a privileged local user obtain a CA credential for a falsified TPM keyCVE-2026-6726 · TCG TPM 2.0 reference code (attestation credential handling, TCG VRT0010)High
- Linux kernel RDS RDMA path net/rds/rdma.c - rds_rdma_pages: The page-count arithmetic for an RDS RDMA scatter-gatherCVE-2010-3865 · Linux kernel RDS RDMA path net/rds/rdma.c - rds_rdma_pagesHigh
- Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cq: Integer overflow on theCVE-2010-4649 · Linux kernel InfiniBand uverbs drivers/infiniband/core/uverbs_cmd.c - ib_uverbs_poll_cqHigh
- Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad): The whole drivers/infinibandCVE-2016-4565 · Linux kernel InfiniBand/RDMA uAPI write() handlers (ib_uverbs, rdma_ucm, ib_ucm, ib_umad)High
- Linux kernel Soft-RoCE drivers/infiniband/sw/rxe/rxe_mr.c (mem_check_range): The bounds check that is supposed toCVE-2016-8636 · Linux kernel Soft-RoCE drivers/infiniband/sw/rxe/rxe_mr.c (mem_check_range)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.