PT-2026-95556 · Intel · Intel Tdx

CVE-2026-92701

·

Published

2026-09-18

·

Updated

2026-09-30

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions versions prior to 0.9.0
Description The intra-handshake attested TLS (aTLS) Intel TDX verification path fails to copy the expected current-session freshness value into the TDX quote-body policy before quote validation. Consequently, structurally valid TDX QuoteV4 Evidence is accepted without verifying that its REPORT DATA field matches the reportData expected for the current session. This allows a relying party to accept Evidence with mismatched or reused reportData and release application data after the handshake, leading to session-misbinding to an unintended attestation context.
Recommendations Update to version 0.9.0.

Exploit

Fix

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92701
GHSA-4PX3-WJ2X-XX47

Affected Products

Intel Tdx