Database/Firmware, BMC & network fabric
Intel Xeon 6 with TDX (protected memory range handling): MULTI-TENANT ISOLATION: Improper handling of overlap
Impact
MULTI-TENANT ISOLATION: Improper handling of overlap between protected memory ranges on Xeon 6 with TDX lets a privileged user escalate. Protected memory range enforcement is how TDX keeps one trust domain's pages away from the host and from other TDs, so overlap handling failing is the isolation primitive itself failing.
Who can reach it
Privileged host user on a Xeon 6 TDX platform.
What to do
OEM platform firmware/BIOS update, not just a TDX module update - which means waiting on your server vendor, a per-node drain and a reboot. Re-attest all trust domains after.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.