CVE-2025-35987
Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur via local access when attack requirements are present with special internal knowledge and requires no user interaction. The potential vulnerability may impact the confidentiality (none), integrity (low) and availability (low) of the vulnerable system, resulting in subsequent system confidentiality (none), integrity (high) and availability (low) impacts.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 4.3
- CVSS vector
- CVSS:4.0/AV:L/AC:H/AT:P/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:H/SA:L
- EPSS probability
- 0.10%
- CWE
- CWE-223
- Published
- 2026-08-11
- Last modified
- 2026-08-12
Affected products
- n/a Intel(R) Software Guard Extensions Data Center Attestation Primitives
Weakness type
Related vulnerabilities
- CVE-2026-49426 — Incorrect audit records for ptrace(2) syscall requests
- CVE-2026-31890 — Inspektor Gadget: Tracing Denial of Service via Event Flooding
- CVE-2025-52926 — In scan.rs in spytrap-adb before 0.3.5, matches for known stalkerware are not rendered in the...
- CVE-2024-52813 — matrix-sdk-crypto missing facility to signal rotation of a verified cryptographic identity
- CVE-2023-31191 — Denial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark Innovations
- CVE-2023-29156 — Denial of Service due to loss of information in DroneScout ds230 Remote ID receiver from BlueMark Innovations
- CVE-2023-28360 — An omission of security-relevant information vulnerability exists in Brave desktop prior to version...
- CVE-2022-44646 — In JetBrains TeamCity version before 2022.10, no audit items were added upon editing a user's...