GPU VulnDB

Database/Firmware, BMC & network fabric

Intel TDX Guest software: incorrect calculation allows privilege escalation inside the trust domain

CVE-2026-20763Firmware, BMC & network fabriccurated

Impact

An incorrect calculation in Intel TDX Guest software before 0.3.1, reachable from ring-3 user applications, may allow escalation of privilege. Intel rates the impact low across confidentiality, integrity and availability with no subsequent-system impact, and the attacker already needs to be a privileged local user in the guest. For a confidential-computing GPU tenant this reads as in-guest hardening rather than a break of the trust-domain boundary: nothing in this record implicates the host, the TDX module, or other trust domains. Worth folding into the next guest image refresh, not an emergency window.

Who can reach it

Local privileged user inside the trust domain — Intel describes a system-software adversary with a privileged user running code in the TDX guest. No user interaction, low attack complexity.

What to do

Update Intel TDX Guest software to 0.3.1 or later in your confidential-computing guest images, per Intel-SA-01462, and restart the affected trust domains so they run the new components. Guest-side only — this advisory calls for no host firmware flash and no microcode update.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.