CVE-2026-20775
Awaiting Analysis Awaiting Analysis - Queue

Intel TDX Module Ring 0 Denial of Service

Vulnerability report for CVE-2026-20775, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-31

Assigner: Intel Corporation

Description

Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust Domain may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (none) and availability (high) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (high) impacts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-31
Generated
2026-09-01
AI Q&A
2026-08-12
EPSS Evaluated
2026-08-30
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
intel tdx_module to 1.5.28 (inc)
intel tdx_module to 2.0.16 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-248 An exception is thrown from a function, but it is not caught.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service vulnerability in Intel TDX modules where a privileged attacker could cause an unhandled exception in Ring 0, leading to system crashes. It requires local access and high complexity but no special knowledge or user interaction.

Detection Guidance

This vulnerability is specific to Intel TDX modules and requires privileged access to exploit. Detection may involve checking for unusual system behavior or logs related to Intel TDX operations. No specific commands are provided in the context.

Impact Analysis

An attacker could exploit this to crash the system, causing downtime and loss of availability. Confidentiality and integrity are not affected, but availability impact is rated high.

Compliance Impact

This vulnerability primarily impacts system availability with high severity, which could disrupt services handling sensitive data. For GDPR, availability issues may affect data subject rights. For HIPAA, it could impact access to protected health information systems. However, specific compliance impacts depend on system context and mitigations.

Mitigation Strategies

Apply Intel-provided updates or patches for TDX modules. Monitor Intel security advisories for mitigation guidance. Restrict privileged user access to reduce attack surface. No specific commands are provided in the context.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-20775. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart