Database/Firmware, BMC & network fabric
Alias Checking Trusted Module (ACTM) firmware for Intel Xeon processors, including Xeon 6: Improper access control
Impact
Improper access control in ACTM, the Intel-signed module that validates memory-aliasing configuration as part of the platform's trusted boot and confidential-computing plumbing on current Xeon parts. An adversary positioned in startup code or SMM can escalate through it, which undermines the platform integrity guarantee that ACTM exists to provide. On the newest Xeon generations this is the layer that a confidential-computing or attestation story is built on, so a defect here means the node's integrity claims to a tenant cannot be relied upon. Persistence obtained at this level is firmware-resident, survives host reimage, and carries into the next tenant occupying the node.
Who can reach it
A privileged adversary already executing in startup code or SMM - reached from local root plus an SMM or early-boot bug, or from a supply-chain-modified BIOS image.
What to do
Platform firmware/BIOS update carrying the fixed ACTM, from the OEM (Dell, HPE, Supermicro, Lenovo, Gigabyte, Quanta, Wiwynn). Host reboot and job drain. This is current-generation silicon, so it directly affects the Xeon 6 head nodes and CPU hosts under new GPU deployments - budget for it in the same maintenance window as GPU firmware. There is no way to disable ACTM, and no host-side mitigation.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.