Database/Firmware, BMC & network fabric
Intel TDX Guest software: incorrect comparison lets a privileged local actor escalate inside a TD guest
Impact
Guest-side Intel TDX software before 0.3.1 performs an incorrect comparison in user-space components, which Intel states may allow escalation of privilege for a local, already-privileged actor. Where confidential computing is used to isolate tenant workloads on accelerated hosts, this is a weakening inside the trust domain the tenant is paying for, not a break of the host-to-guest boundary. Intel rates the impact low across confidentiality, integrity and availability with no subsequent-system impact, and the record does not name the specific component or the escalation path. Nothing in the record indicates the host, the hypervisor or another tenant's TD can reach it.
Who can reach it
Local access inside the trust domain with a privileged (administrative) account in the guest; no user interaction. Not reachable across the network or from another tenant.
What to do
Update Intel TDX Guest software to version 0.3.1 or later per INTEL-SA-01462. This is a guest-side package update: refresh the confidential-VM image or update in place and restart the affected trust domains. Intel's record describes no microcode update, BIOS flash or host reboot for this issue, and does not list a mitigation for unpatched guests.
References
Related entries
- Dell OpenManage Enterprise: low-privileged user can inject script into the console and expose informationCVE-2026-54793 · Dell OpenManage Enterprise (web console cross-site scripting)Medium
- Lenovo XClarity Controller: Backup/restore password written to an internal XCC log bufferCVE-2021-3473 · Lenovo XClarity ControllerMedium
- Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000: The patched ME firmware doesCVE-2017-5698 · Intel AMT / ISM / SBT firmware anti-rollback, ME 11.0.25.3001 and 11.0.26.3000Medium
- Intel SGX protected memory subsystem: Insufficient access control in the SGX protected-memory subsystem allowsCVE-2019-0117 · Intel SGX protected memory subsystemMedium
- Intel E810 Ethernet controller firmware (NVM < 1.4.1.13): Early-generation E810 firmware flaw (an access-controlCVE-2020-24497 · Intel E810 Ethernet controller firmware (NVM < 1.4.1.13)Medium
- Intel E810 Ethernet controller firmware: privileged-local buffer overflows allow denial of serviceCVE-2020-24498 · Intel E810 Ethernet controller firmware (NVM < 1.4.1.13)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.