Database/Firmware, BMC & network fabric
Intel TDX module: uncaught exception lets privileged host software deny service to trust domains
Impact
An uncaught exception in the TDX module can be triggered by privileged host software, producing high availability impact on the vulnerable system and on the trust domains it hosts. On a confidential-computing GPU node this means every tenant TD on that host goes down together, and recovery is a node-level event rather than a per-VM restart. The practical exposure is a host-side stability and blast-radius problem: one privileged fault takes out the whole confidential workload set on the box. Intel rates the attack high complexity and it requires privileged local access, so it is not a path an ordinary tenant can reach.
Who can reach it
Local, from privileged system software on the host (Ring 0 / VMM level). No remote or unauthenticated path.
What to do
Apply the updated Intel TDX module per Intel SA-01436, the same advisory that covers CVE-2026-20705 - fix both in one maintenance window. Delivery is through Intel/OEM platform firmware channels: drain trust domains, apply the update, reboot the node. Intel's advisory is the authority on the fixed module version and the exact affected Xeon SKUs.
References
Related entries
- Intel TDX module: insecure storage of sensitive information exposes trust domain data to Ring 0 softwareCVE-2026-20705 · Intel TDX module (Trust Domain Extensions, 4th/5th Gen Xeon Scalable)Medium
- NVIDIA UFM Enterprise: crafted user-management API request lets an admin inject commands on the fabric managerCVE-2026-24167 · NVIDIA UFM Enterprise (user management API)Medium
- NVIDIA UFM Enterprise: IBDiagnet API accepts crafted requests that inject commands on the fabric manager hostCVE-2026-24168 · NVIDIA UFM Enterprise (IBDiagnet API)Medium
- OpenBMC bmcweb mTLS client-certificate UPN validation: Where mTLS is configured, bmcweb matches the certificate's UPNNCVD-2026-004-openbmc-bmcweb-mtls-client-certi · OpenBMC bmcweb mTLS client-certificate UPN validationMedium
- Cisco NX-OS CLI: CLI command injection giving root-level execution on the switch OS for an authenticated adminCVE-2017-12334 · Cisco NX-OS CLIMedium
- Intel Server Board / Server System / Compute Module platform firmware: Improper memory initialisation in platformCVE-2018-12204 · Intel Server Board / Server System / Compute Module platform firmwareMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.