CVE-2026-20705CWE-922

CVE-2026-20705

Medium · published August 11, 2026

CVSS v3.1
5.3
EPSS
0%
Percentile
1.1
In the wild
Unconfirmed
What it is

Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.

The record
Technical detail
CVSS v3.1
5.3 · MEDIUM
Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00105 · 1.1th percentile
Weakness
CWE-922 · Insecure Storage of Sensitive Information
Published
2026-08-11T21:17Z
Affected products (4)
ProductVersionsFixed in
intel/tdx_module≤ 1.5.28
intel/tdx_module≤ 1.5.28
intel/tdx_module≤ 2.0.16
intel/tdx_module≤ 2.0.16
References (1)
EPSS history
Timeline
  • 11 AUG 16:25Z
    Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure
    cvelistv5