GPU VulnDB

Database/Firmware, BMC & network fabric

Intel Xeon 6 with TDX (protected memory range handling): Improper handling of overlap between protected memory ranges

CVSS 7.9CVE-2025-22889Firmware, BMC & network fabriccurated

Impact

Improper handling of overlap between protected memory ranges on Xeon 6 with TDX lets a privileged user escalate. Protected memory range enforcement is how TDX keeps one trust domain's pages away from the host and from other TDs, so overlap handling failing is the isolation primitive itself failing.

Who can reach it

Privileged host user on a Xeon 6 TDX platform.

What to do

OEM platform firmware/BIOS update, not just a TDX module update - which means waiting on your server vendor, a per-node drain and a reboot. Re-attest all trust domains after.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.