Executive brief
Intel Trust Domain Extensions (TDX) is a security feature in Xeon processors that protects sensitive workloads from unauthorized access. An uncaught exception in the TDX module can be triggered by a privileged attacker to crash the system or disable TDX protections, causing service outages and disrupting business-critical applications running in trusted domains.
Technical details
This vulnerability is an uncaught exception (improper error handling) in Intel TDX modules running in Ring 0 (the highest privilege level). The flaw exists in 4th Gen, 5th Gen Intel Xeon Scalable processors, and Intel Xeon 6 processors with P-cores and SoC variants. A system software adversary with high privileges can trigger the exception via local access to cause a denial of service. The attack requires high complexity and privileged access (PR:H) but no user interaction. Intel has released firmware mitigations; users should update to the latest TDX module version provided by their system manufacturer.
Affected products
- Intel 4th Gen Xeon Scalable processor 1.5.28 and earlier
- Intel 5th Gen Xeon Scalable processor 1.5.28 and earlier
- Intel Xeon 6 processor with P-cores 2.0.16 and earlier
- Intel Xeon 6 SoC 2.0.16 and earlier
Timeline
- 2026-08-11: disclosed: CVE-2026-20775 published in INTEL-SA-01436