GPU VulnDB

Database/Firmware, BMC & network fabric

Intel Xeon processors (SGX/TDX error injection): MULTI-TENANT ISOLATION: Unauthorised error injection against SGX

CVE-2022-41804Firmware, BMC & network fabriccurated

Impact

MULTI-TENANT ISOLATION: Unauthorised error injection against SGX or TDX on affected Xeon parts gives a privileged user an escalation. Fault injection against a TEE is the same family as Plundervolt: the host corrupts the protected computation until it gives up its secrets.

Who can reach it

Privileged local access on the host.

What to do

Microcode update - late-loadable at boot on most distributions, so this one does not wait on an OEM BIOS release - plus a TCB recovery and re-attestation. Reboot required.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.