Executive brief
Intel's Trust Domain Extensions (TDX) module, a security feature used in Xeon processors to isolate and protect sensitive workloads, contains improper authentication in its Ring 0 (kernel-level) Trust Domain component. An attacker with privileged system software access and high technical complexity can bypass authentication controls to disclose sensitive information or escalate privileges. This could allow compromise of confidential data processed by TDX-protected applications and gain deeper control over the system.
Technical details
CVE-2026-20885 is an improper authentication vulnerability in the Intel TDX module's Ring 0 Trust Domain component. The vulnerability requires local access combined with high attack complexity and privileged user context; it is not remotely exploitable. A system software adversary with elevated privileges can exploit this to achieve information disclosure and privilege escalation. The vulnerability has a CVSS 4.0 score of 7.0 with vector CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N. Intel has released firmware updates as mitigations; system administrators should apply vendor-provided patches.
Affected products
- Intel TDX module 1.5.28 and earlier (4th/5th Gen Xeon Scalable); 2.0.16 and earlier (Xeon 6)
- Intel 4th Gen Xeon Scalable processor 1.5.28 and earlier
- Intel 5th Gen Xeon Scalable processor 1.5.28 and earlier
- Intel Xeon 6 processor with P-cores 2.0.16 and earlier
- Intel Xeon 6 SoC 2.0.16 and earlier
Timeline
- 2026-08-11: disclosed: CVE-2026-20885 publicly disclosed via Intel security advisory INTEL-SA-01436