Intel TDX Modules Ring 0 Hypervisor Out-of-Bounds Read Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing out-of-bounds read has been identified in some Intel Trust Domain Extensions (TDX) modules prior to version 1.5.24, within Ring 0: Hypervisor. This vulnerability may lead to unauthorized information disclosure. It can be exploited by an authorized adversary with privileged user access, through a low complexity attack, potentially via local access. The exploitation requires no user interaction and can occur without special internal knowledge. The vulnerability impacts the confidentiality of the system, while integrity and availability remain unaffected.

Impact

Exploitation of this vulnerability could result in unauthorized information disclosure, allowing sensitive data to be exposed.

Remediation

Users of affected Intel Xeon processors are advised to update to the latest version provided by their system manufacturer that addresses this vulnerability.

Added: Feb 10, 2026, 5:26 PM
Updated: Feb 11, 2026, 2:24 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.8
exploitability
2.8
remediation
0.0
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.