Skip to main content

Insufficient Control Flow Management

CVE-2024-21801

Severity High
Score 8.3/10

Summary

Insufficient control flow management in some Intel(R) TDX module software before version 1.5.05.46.698 may allow a privileged user to potentially enable denial of service via local access.

  • LOW
  • LOCAL
  • NONE
  • CHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-691 - Insufficient Control Flow Management

The code does not sufficiently manage its control flow during execution, creating conditions in which the control flow can be modified in unexpected ways.

References

Advisory Timeline

  • Published