Junglewise Threat Intelligence

CVE-2026-20705: Intel TDX module insecure storage of sensitive information

CVE-2026-20705 · Severity: medium · CVSS 5.3 · Published 2026-08-11

Technologies: Intel Xeon 6 processor with P-cores, Intel 4th Gen Xeon Scalable processor, Intel Xeon 6 SoC, Intel 5th Gen Xeon Scalable processor. Vendors: Intel.

Executive brief

Intel's TDX (Trust Domain Extensions) module, a security component used in enterprise processors to isolate and protect sensitive workloads, contains a flaw that allows an authenticated privileged attacker with physical access or high-level system access to read sensitive data from memory. An attacker exploiting this vulnerability could gain unauthorized access to confidential information stored within protected trust domains, potentially compromising customer data and system security.

Technical details

The vulnerability is a case of insecure storage of sensitive information in the Intel TDX module's Ring 0 Trust Domain, allowing information disclosure. The attack requires a system software adversary with privileged user access and involves high complexity attack conditions, exploitable via local access without special internal knowledge or user interaction. An attacker can read sensitive data from memory that should have been protected by the TDX isolation mechanism. Intel recommends updating the TDX module firmware through system manufacturers; affected versions include 4th Gen Xeon Scalable (1.5.28 and earlier), 5th Gen Xeon Scalable (1.5.28 and earlier), Xeon 6 with P-cores (2.0.16 and earlier), and Xeon 6 SoC (2.0.16 and earlier).

Affected products

  • Intel 4th Gen Xeon Scalable processor 1.5.28 and earlier
  • Intel 5th Gen Xeon Scalable processor 1.5.28 and earlier
  • Intel Xeon 6 processor with P-cores 2.0.16 and earlier
  • Intel Xeon 6 SoC 2.0.16 and earlier

Timeline

  • 2026-08-11: disclosed

References

Related threats