Database/Firmware, BMC & network fabric
Intel Xeon 6 with TDX: overlapping protected memory ranges in SMM allow privilege escalation
Impact
Improper handling of overlap between protected memory ranges on some Xeon 6 processors using Intel TDX lets an adversary already executing in System Management Mode, combined with a privileged user, escalate privilege with high confidentiality and integrity impact. For a GPU cloud, TDX is the thing that lets a customer run a confidential VM on shared hardware without trusting the operator; a flaw that lets SMM code reach across the protected memory boundary weakens exactly that guarantee. Intel marks it high attack complexity requiring special internal knowledge and existing SMM privilege, so this is not a tenant-reachable bug - it matters as an erosion of the confidential-computing attestation story you sell, and for anyone whose threat model includes a compromised or malicious firmware layer. Availability is unaffected and the scored impact does not propagate beyond the vulnerable system.
Who can reach it
Local, requiring high privilege: an adversary already running code in SMM (i.e. having compromised or being able to supply system firmware) together with a privileged user on the host. Not reachable from a tenant VM or a GPU pod.
What to do
Apply the platform firmware/BIOS update from your server vendor that carries Intel's fix per INTEL-SA-01379; on Xeon 6 this ships as a BIOS/microcode bundle, so each affected host must be drained and rebooted into the new firmware. Intel's advisory is the authority on which SKUs and firmware versions are fixed - check it against your exact Xeon 6 models before scheduling the window. There is no runtime mitigation short of not relying on TDX isolation against a firmware-level adversary.
References
Related entries
- EDK II (SMM environment, Machine Check Exception handling): Machine Check Exceptions are enabled before SMM installsCVE-2025-3770 · EDK II (SMM environment, Machine Check Exception handling)High
- Lenovo XClarity Orchestrator: microservices accept invalid TLS certificates, exposing management trafficCVE-2026-16792 · Lenovo XClarity Orchestrator 2.2.0 (microservice TLS certificate validation)High
- Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436: Improper authenticationCVE-2026-20885 · Intel TDX module, Ring 0 / Trust Domain context, multiple Intel platforms - INTEL-SA-01436High
- Arista EOS: crafted OSPFv3 packets restart the Ospf3 agent and drop all adjacenciesCVE-2026-73438 · Arista EOS Ospf3 agent (OSPFv3 packet handling)High
- Arista EOS: crafted IS-IS Hello PDU tears down an established adjacency on a broadcast linkCVE-2026-73446 · Arista EOS IS-IS (Hello PDU handling on broadcast interfaces)High
- Arista EOS: spoofed dual-primary packets make the MLAG secondary err-disable its interfacesCVE-2026-73450 · Arista EOS MLAG Dual Primary DetectionHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.