GPU VulnDB

Database/Firmware, BMC & network fabric

Intel Xeon 6 with TDX (protected memory range handling): MULTI-TENANT ISOLATION: Improper handling of overlap

CVE-2025-22889Firmware, BMC & network fabriccurated

Impact

MULTI-TENANT ISOLATION: Improper handling of overlap between protected memory ranges on Xeon 6 with TDX lets a privileged user escalate. Protected memory range enforcement is how TDX keeps one trust domain's pages away from the host and from other TDs, so overlap handling failing is the isolation primitive itself failing.

Who can reach it

Privileged host user on a Xeon 6 TDX platform.

What to do

OEM platform firmware/BIOS update, not just a TDX module update - which means waiting on your server vendor, a per-node drain and a reboot. Re-attest all trust domains after.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.