Junglewise Threat Intelligence

CVE-2026-20775: Intel TDX module uncaught exception denial of service

CVE-2026-20775 · Severity: medium · CVSS 5.3 · Published 2026-08-11

Technologies: Intel 5th Gen Xeon Scalable processor, Intel 4th Gen Xeon Scalable processor, Intel Xeon 6 processor with P-cores, Intel Xeon 6 SoC. Vendors: Intel.

Executive brief

Intel Trust Domain Extensions (TDX) is a security feature in Xeon processors that protects sensitive workloads from unauthorized access. An uncaught exception in the TDX module can be triggered by a privileged attacker to crash the system or disable TDX protections, causing service outages and disrupting business-critical applications running in trusted domains.

Technical details

This vulnerability is an uncaught exception (improper error handling) in Intel TDX modules running in Ring 0 (the highest privilege level). The flaw exists in 4th Gen, 5th Gen Intel Xeon Scalable processors, and Intel Xeon 6 processors with P-cores and SoC variants. A system software adversary with high privileges can trigger the exception via local access to cause a denial of service. The attack requires high complexity and privileged access (PR:H) but no user interaction. Intel has released firmware mitigations; users should update to the latest TDX module version provided by their system manufacturer.

Affected products

  • Intel 4th Gen Xeon Scalable processor 1.5.28 and earlier
  • Intel 5th Gen Xeon Scalable processor 1.5.28 and earlier
  • Intel Xeon 6 processor with P-cores 2.0.16 and earlier
  • Intel Xeon 6 SoC 2.0.16 and earlier

Timeline

  • 2026-08-11: disclosed: CVE-2026-20775 published in INTEL-SA-01436

References

Related threats