Executive brief
Intel Trust Domain Extensions (TDX) is a processor security feature that isolates sensitive workloads in virtualized environments. A vulnerability in TDX's data authenticity verification could allow privileged attackers to read sensitive information from protected memory regions. Exploitation requires local access and high system privileges, but successful attacks could expose confidential data processed within these isolated domains.
Technical details
This vulnerability is a cryptographic verification flaw in Intel TDX's Ring 0 (hypervisor-level) authenticity checks. An attacker with high privilege (PR:H) can exploit insufficient data authenticity verification to bypass TDX isolation guarantees and disclose information from trusted execution domains. The attack vector is local (AV:L), requires high complexity (AC:H) and specific system prerequisites (AT:P), but requires no user interaction. Exploitation results in high confidentiality impact and low integrity impact. Intel has released firmware updates for affected Xeon Scalable processors to mitigate this issue.
Affected products
- Intel Xeon Scalable (4th Gen) 1.5.24 and earlier
- Intel Xeon Scalable (5th Gen) 1.5.24 and earlier
- Intel Xeon 6 with P-cores 2.0.14 and earlier
- Intel Xeon 6 SoC 2.0.14 and earlier
- Intel Xeon 6 with E-cores 1.5.24 and earlier
Timeline
- 2026-08-11: disclosed