Database/Firmware, BMC & network fabric
Intel Xeon 6 with TDX: coarse access control in a processor subsystem exposes data to an authenticated local user
Impact
Insufficient granularity of access control in a processor subsystem lets an authenticated local user read data they should not reach, with the confidentiality damage landing on a component other than the one that is flawed - Intel scores the vulnerable system itself as unaffected and the subsequent system confidentiality impact as high. On a shared GPU host running TDX trust domains, that means a tenant or service account with a local login is the relevant starting point, not just the hypervisor. Intel requires high attack complexity and 'special internal knowledge', so exploitation is not casual. Head node and bastion hosts where many users hold shells are the places this matters most.
Who can reach it
Local, authenticated user on an affected Xeon 6 host with TDX enabled. No user interaction needed, but the attack is high complexity and depends on internal platform knowledge.
What to do
Apply the platform update referenced in Intel SA-01404 through your server OEM's BIOS/firmware bundle; these land at boot, so plan to drain and reboot each affected Xeon 6 node. The record gives no fixed version - read the advisory for the level your OEM publishes.
References
Related entries
- Self-encrypting drives in TCG Opal / eDrive modeCVE-2015-7267 · Self-encrypting drives in TCG Opal / eDrive mode - Samsung 850 Pro, Samsung PM851, Seagate ST500LT015, ST500LT025 on…Medium
- Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commands: The driveCVE-2018-12038 · Samsung 840 EVO SSD - disk encryption key exposed through wear-levelled NAND and vendor-specific commandsMedium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2025-20044 · Intel TDX moduleMedium
- Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode)CVE-2018-12037 · Crucial/Micron MX100, MX200, MX300; Samsung 840 EVO and 850 EVO (ATA-high mode); Samsung T3 and T5 portable SSDs…Medium
- AMD processors - speculative reordering of loads on shared memory: AMD processors may speculatively reorder loadCVE-2021-26400 · AMD processors - speculative reordering of loads on shared memoryMedium
- AMD SEV firmware - SEV-ES guest attacking an SNP guest: Coarse access-control granularity in SEV firmware lets aCVE-2025-48514 · AMD SEV firmware - SEV-ES guest attacking an SNP guestMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.