CVE-2026-20705: Medium severity Intel Intel(R) TDX module vulnerability
Insecure storage of sensitive information in the Intel(R) TDX module for some Intel(R) platform within Ring 0: Trust Domain may allow information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (high), integrity (none) and availability (none) impacts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20705?
The severity of CVE-2026-20705 is rated as risk 38.
How do I fix CVE-2026-20705?
To address CVE-2026-20705, update the Intel(R) TDX module to the latest patched version provided by Intel.
What kind of data is at risk in CVE-2026-20705?
CVE-2026-20705 involves the insecure storage of sensitive information within the Intel(R) TDX module.
Who is affected by CVE-2026-20705?
CVE-2026-20705 affects users of Intel(R) platforms utilizing the Intel(R) TDX module.
What type of attack is associated with CVE-2026-20705?
CVE-2026-20705 may allow data exposure through a high complexity attack from a system software adversary with privileged access.