VDB

CVE-2025-27940

CVE-2025-27940 PUBLISHED CVSS 4.099999904632568 MEDIUM

Out-of-bounds read for some TDX Module before version tdx1.5 within Ring 0: Hypervisor may allow an information disclosure. Software side channel adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack requirements are present without special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (high), integrity (none) and availability (none) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (none) and availability (none) impacts.

EPSS 0.02% · 4.5th percentile

Risk Scores

CVSS v3.1
4.099999904632568
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.02%
4.5th percentile

Affected Products

VendorProductVersions
n/aTDX Modulebefore version tdx1.5, before version tdx1.5

Timeline

  • Apr 15, 2025 CVE ID Reserved
  • Feb 10, 2026 CVE Published
  • Feb 10, 2026 CVE Updated
  • Feb 11, 2026 EPSS Score
  • Feb 11, 2026 PoC Published
  • Feb 13, 2026 EPSS Score
  • Feb 15, 2026 EPSS Score
  • Feb 17, 2026 EPSS Score
  • Feb 19, 2026 EPSS Score
  • Feb 21, 2026 EPSS Score
  • Feb 23, 2026 EPSS Score
  • Feb 25, 2026 EPSS Score

References

Open in Interactive Console →
$ Console Community · 100/wk Open console ›