GPU VulnDB

Database/Firmware, BMC & network fabric

Intel TDX: insufficient verification of data authenticity in the ring 0 interface leaks trust-domain data

CVSS 5.7CVE-2025-31356Firmware, BMC & network fabriccurated

Impact

A privileged host-software adversary - the hypervisor or anyone who has taken it - can get confidential data out of a TDX trust domain, which is exactly the boundary TDX exists to hold. For an operator renting confidential GPU VMs or selling attested enclaves to customers, this weakens the claim that the platform owner cannot see tenant data; the guest has no way to detect or mitigate it from the inside. Intel rates it 5.7 and marks the attack as high complexity with privileged local access required, so this is a trust-guarantee erosion rather than a break-glass emergency. It does not give a tenant a path out of its own VM.

Who can reach it

Local, from privileged host system software (ring 0 hypervisor context). Not reachable by an unprivileged tenant or over the network; requires an already-privileged position on the host plus a high-complexity attack.

What to do

Follow Intel SA-01419. TDX fixes are delivered as platform firmware/TDX module updates that take effect at boot, so budget draining the node and rebooting it rather than a live patch. The record names no fixed version - check the advisory for the module/BIOS level your OEM ships before scheduling the window.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.