Database/Firmware, BMC & network fabric
Intel Xeon 6 memory subsystem (with SGX or TDX): An out-of-bounds write in the Xeon 6 memory subsystem reachable when
CVSS 7.2CVE-2025-26403Firmware, BMC & network fabriccurated
Impact
An out-of-bounds write in the Xeon 6 memory subsystem reachable when SGX or TDX is enabled, escalating privilege for a privileged local user. An OOB write in the memory subsystem of a confidential-compute platform undercuts both the SGX and the TDX guarantee on the same silicon.
Who can reach it
Privileged local access on a Xeon 6 host with SGX or TDX enabled.
What to do
OEM platform firmware/BIOS update, plus TDX module and SGX TCB recovery as applicable. Drain and reboot; re-attest every TD and enclave afterwards.
References
Related entries
- Intel Xeon 6 DDRIO configuration (with SGX or TDX): An improperly implemented security check in DDRIO configuration onCVE-2025-32086 · Intel Xeon 6 DDRIO configuration (with SGX or TDX)High
- AMI AptioV UEFI BIOS: Improper handling of insufficient permissions in the BIOS lets a low-privileged local userCVE-2025-58770 · AMI AptioV UEFI BIOSHigh
- Supermicro BMC firmware validation (MBD-X13SEM-F): Second-generation RoT bypassCVE-2025-6198 · Supermicro BMC firmware validation (MBD-X13SEM-F)High
- AMD Pensando ionic driver on ESXi: untrusted pointer dereference lets a guest VM read kernel and co-tenant memoryCVE-2025-62627 · AMD Pensando ionic cloud driver for VMware ESXi (DPU datapath)High
- Supermicro BMC firmware validation (MBD-X12STW): RoT bypass, crafted firmware image acceptedCVE-2025-7937 · Supermicro BMC firmware validation (MBD-X12STW)High
- Supermicro BMC web server request handling on MBD-X13SEDW-F: Any account that can log into the BMC web interface canCVE-2025-8076 · Supermicro BMC web server request handling on MBD-X13SEDW-FHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.