Executive brief
Intel's Trust Domain Extensions Data Center Attestation Primitives (TDX DCAP) is a software library used by data centers to verify the security and integrity of trust domains in Intel processors. A vulnerability in the Quote Verification Library can cause denial of service by omitting security-relevant information that customers need for platform security verification, potentially preventing secure attestation operations from completing successfully.
Technical details
This vulnerability involves omission of security-relevant information in Intel Software Guard Extensions Data Center Attestation Primitives' Quote Verification Library. The flaw is classified as an information disclosure affecting the Ring 0 kernel component, with CVSS 4.3 (Medium). Exploitation requires local access combined with high complexity attack conditions, privileged (high) access rights, and special internal knowledge. An authorized privileged adversary can exploit this to enable data alteration and cause denial of service by rendering platform security verification incomplete. The vulnerability affects versions 1.14 through 1.23; Intel recommends updating to version 1.24 or later.
Affected products
- Intel Trust Domain Extensions Data Center Attestation Primitives 1.14 to 1.23
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Fixed in version 1.24