Database/Firmware, BMC & network fabric
Intel Xeon 6 memory subsystem (with SGX or TDX): MULTI-TENANT ISOLATION: An out-of-bounds write in the Xeon 6 memory
CVE-2025-26403Firmware, BMC & network fabriccurated
Impact
MULTI-TENANT ISOLATION: An out-of-bounds write in the Xeon 6 memory subsystem reachable when SGX or TDX is enabled, escalating privilege for a privileged local user. An OOB write in the memory subsystem of a confidential-compute platform undercuts both the SGX and the TDX guarantee on the same silicon.
Who can reach it
Privileged local access on a Xeon 6 host with SGX or TDX enabled.
What to do
OEM platform firmware/BIOS update, plus TDX module and SGX TCB recovery as applicable. Drain and reboot; re-attest every TD and enclave afterwards.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.