GPU VulnDB

Database/Firmware, BMC & network fabric

Intel Xeon 6 with TDX: coarse access control in a processor subsystem exposes data to an authenticated local user

CVSS 4.3CVE-2025-31938Firmware, BMC & network fabriccurated

Impact

Insufficient granularity of access control in a processor subsystem lets an authenticated local user read data they should not reach, with the confidentiality damage landing on a component other than the one that is flawed - Intel scores the vulnerable system itself as unaffected and the subsequent system confidentiality impact as high. On a shared GPU host running TDX trust domains, that means a tenant or service account with a local login is the relevant starting point, not just the hypervisor. Intel requires high attack complexity and 'special internal knowledge', so exploitation is not casual. Head node and bastion hosts where many users hold shells are the places this matters most.

Who can reach it

Local, authenticated user on an affected Xeon 6 host with TDX enabled. No user interaction needed, but the attack is high complexity and depends on internal platform knowledge.

What to do

Apply the platform update referenced in Intel SA-01404 through your server OEM's BIOS/firmware bundle; these land at boot, so plan to drain and reboot each affected Xeon 6 node. The record gives no fixed version - read the advisory for the level your OEM publishes.

References

Related entries

All Firmware, BMC & network fabric entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.