Description
Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (low) impacts.
Published: 2026-08-11
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An omission in the handling of security‑relevant information within Intel R Software Guard Extensions (SGX) Data Center Attestation Primitives can allow a kernel to perform an action that may result in denial of service or data alteration. The flaw is formally identified as CWE‑223 (Incorrect Token Validation) and, according to the description, can lead to integrity impact rated as high while availability impact remains low and confidentiality is unaffected. The CVSS score of 4.3 indicates a low overall severity, yet the potential to modify data with elevated privileges makes the issue relevant for environments where integrity is critical.

Affected Systems

Intel R Software Guard Extensions Data Center Attestation Primitives are the affected products. No version information is disclosed in the advisory, so all builds using this component are potentially impacted.

Risk and Exploitability

The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog, suggesting that exploitation is unlikely at present. However, the attack requires a privileged user and a high‑complexity local attack with no user interaction. If such conditions are met, an attacker could cause system instability or alter sensitive data. The low CVSS score and minimal exploitation probability reduce the urgency, but the potential integrity impact warrants careful monitoring.

Generated by OpenCVE AI on August 12, 2026 at 21:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply Intel SGX Data Center Attestation Primitive updates as soon as they become available.
  • Limit privileged user accounts and enforce least‑privilege principles to reduce the likelihood that an attacker can reach kernel mode.
  • Monitor kernel logs for abnormal activity such as unexpected memory changes or crashes that may indicate exploitation.

Generated by OpenCVE AI on August 12, 2026 at 21:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Intel
Intel software Guard Extensions Data Center Attestation Primitives
Vendors & Products Intel
Intel software Guard Extensions Data Center Attestation Primitives

Wed, 12 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Title Kernel Denial of Service in Intel SGX Data Center Attestation Primitives

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Description Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (low) impacts.
Weaknesses CWE-223
References
Metrics cvssV4_0

{'score': 4.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:L'}


Subscriptions

Intel Software Guard Extensions Data Center Attestation Primitives
cve-icon MITRE

Status: PUBLISHED

Assigner: intel

Published:

Updated: 2026-08-12T18:49:01.648Z

Reserved: 2025-04-15T21:26:10.393Z

Link: CVE-2025-35987

cve-icon Vulnrichment

Updated: 2026-08-12T18:48:56.907Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T17:17:43.923

Modified: 2026-08-12T20:54:11.500

Link: CVE-2025-35987

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:30:04Z

Weaknesses
  • CWE-223

    Omission of Security-relevant Information