CVE Vulnerabilities

CVE-2024-39283

Incomplete Filtering of Special Elements

Published: Aug 14, 2024 | Modified: Sep 12, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Incomplete filtering of special elements in Intel(R) TDX module software before version TDX_1.5.01.00.592 may allow an authenticated user to potentially enable escalation of privilege via local access.

Weakness

The product receives data from an upstream component, but does not completely filter special elements before sending it to a downstream component.

Affected Software

Name Vendor Start Version End Version
Tdx_module_software Intel * 1.5.01.00.592 (excluding)

References