Platform Security Guidance
Trusted Computing Base Recovery Attestation
Intel's Confidential Computing solutions enable end-to-end data protection using silicon-rooted Trusted Execution Environments (TEEs) such as Intel® Software Guard Extensions (Intel® SGX) and Intel® Trust Domain Extensions (Intel® TDX). These technologies secure application and virtual machine data, and support attestation, allowing external parties to cryptographically verify the integrity of the TEE and the data processed within it.
When Trusted Computing Base (TCB) components require updates to maintain a strong security posture, Intel initiates a TCB Recovery (TCB-R) process, to add the latest signed components to the TCB. All relevant parties must deploy these updates so that relying parties can use attestation to compare their platform’s report with a signed reference and make informed trust decisions.
For guidance on the TCB-R process for Intel technologies, including policies and best practices for attestation, see the Trusted Computing Base Recovery of Intel Trusted Execution Environments article.
Affected Processors: Trusted Computing Base Recovery Attestation
This table shows all currently supported Intel platforms that support Intel SGX or Intel TDX. For platforms that participate in TCB-R, the action required to perform a successful recovery is listed by disclosure, with the accompanying security advisory (SA) from Intel listed for more information.
Processors are listed by product family. For specific product names, see Product Specifications. Product families that do not support Intel SGX or Intel TDX are not listed in this table. Processors that have met the End of Servicing Lifetime (EOSL) milestone may not be listed in the following table, and the mitigation status of EOSL processors may not be evaluated. For more information on processors that are no longer supported and not listed in the table, see Support.
A .csv version of this table is also available on GitHub*.
| CPUID Family_Model |
Stepping | CPUID Hybrid Identification |
Code Name(s) / Microarchitecture(s) | Product Family | Segment | CPUID1 | MCU Update2 where applicable |
Metadata Inconsistency CVE-2026-20702 INTEL-SA-01449 |
Intel TDX Security CVE-2026-20885 CVE-2026-20705 CVE-2026-20775 INTEL-SA-01436 |
QVL Reporting CVE-2025-35987 INTEL-SA-01421 |
Migration TCB Mismatch CVE-2025-31356 INTEL-SA-01419 |
BMC MSR Leak CVE-2025-31938 INTEL-SA-01404 |
Register Range Overlap CVE-2025-31936 INTEL-SA-01379 |
MCHECK DIMMs CVE-2026-20713 CVE-2026-20901 INTEL-SA-01442 |
ACTM Memory Access CVE-2026-20898 INTEL-SA-01439 |
Ucode Memory Protection CVE-2025-35973 INTEL-SA-01428 |
Zero-at-ret CVE-2026-20917 INTEL-SA-01423 |
OOB Read/TDX CVE-2025-30513, CVE-2025-31944, CVE-2025-32007, CVE-2025-32467, INTEL-SA-01397 |
OOB Write/TDX CVE-2025-22885 INTEL-SA-01314 |
OOB Write/MCHECK CVE-2025-32086 CVE-2025-26403 INTEL-SA-01367 |
Control Flow in ACTM/MCHECK CVE-2025-24305 CVE-2025-20053 CVE-2025-21090 INTEL-SA-01313 |
Shared Resources CVE-2025-22853; CVE-2025-21096 INTEL-SA-01312 |
Memory Overlap CVE-2025-22889 INTEL-SA-01311 |
Firmware Lock CVE-2025-20044 INTEL-SA-01245 |
Max_vcpu CVE-2024-33607 INTEL-SA-01192 |
Indirect Target Selection (IBPB) CVE-2024-28956 INTEL-SA-01153 |
Processor Trace CVE-2024-48869 INTEL-SA-01268 |
Mcheck TOCTOU CVE-2025-20100 INTEL SA-01278 |
ACTM MRDIMM CVE-2025-2004 INTEL SA-01273 |
Improper Input Validation CVE-2023-45745 INTEL-SA-01036 |
Running Average Power Limit Derivative (RAPL) CVE-2024-23984 INTEL-SA-01103 |
Single-stepping Counter Bypass CVE-2024-27457 INTEL-SA-01099 |
Invalid DIMM and RFM CVE-2024-22185 INTEL-SA-01111 |
Incorrect Default CVE-2024-21820 INTEL-SA-01079 |
Resource Reuse CVE-2024-21850 INTEL-SA-01076 |
Incomplete Filtering CVE-2024-39283 INTEL-SA-01010 |
Microcode Keying CVE-2023-43490 INTEL-SA-01045 |
Register File Data Sampling (RFDS) (Floating Point/Integer / Single Instruction/Multiple Data) CVE-2023-28746 INTEL-SA-00898 |
On-chip Debug and Interface CVE-2023-32666 INTEL-SA-00986 |
Trusted Execution Configuration Register Access CVE-2023-22655 INTEL-SA-00960 |
Incomplete Branch Prediction Barrier CVE-2023-38575 INTEL-SA-00982 |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| TCB-R Counter:TBD | TCB-R Counter:22 IPU 26.3 (August 2026) |
TCB-R Counter:TBD | TCB-R Counter:22 IPU 26.3 (August 2026) |
TCB-R Counter:22 IPU 26.3 (August 2026) |
TCB-R Counter:22 IPU 26.3 (August 2026) |
TCB-R Counter:22 IPU 26.3 (August 2026) |
TCB-R Counter:22 IPU 26.3 (August 2026) |
TCB-R Counter:22 IPU 26.3 (August 2026) |
TCB-R Counter:22 IPU 26.3 (August 2026) |
TCB-R Counter:21 IPU 26.1 (February 2026) |
TCB-R Counter:21 IPU 26.1 (February 2026) |
TCB-R Counter:20 IPU 25.3 (August 2025) |
TCB-R Counter:20 IPU 25.3 (August 2025) |
TCB-R Counter:20 IPU 25.3 (August 2025) |
TCB-R Counter:20 IPU 25.3 (August 2025) |
TCB-R Counter:20 IPU 25.3 (August 2025) |
TCB-R Counter:20 IPU 25.3 (August 2025) |
TCB-R Counter:19 IPU 25.2 (May 2025) |
TCB-R Counter:19 IPU 25.2 (May 2025) |
TCB-R Counter:19 IPU 25.2 (May 2025) |
TCB-R Counter:19 IPU 25.2 (May 2025) |
TCB-R Counter:18 IPU 24.3 / UPLR2 (Sept, Nov 2024) |
TCB-R Counter:18 IPU 24.3 / UPLR2 (Sept, Nov 2024) |
TCB-R Counter:18 IPU 24.3 / UPLR2 (Sept, Nov 2024) |
TCB-R Counter:18 IPU 24.3 / UPLR2 (Sept, Nov 2024) |
TCB-R Counter:18 IPU 24.3 / UPLR2 (Sept, Nov 2024) |
TCB-R Counter:18 IPU 24.3 / UPLR2 (Sept, Nov 2024) |
TCB-R Counter:18 IPU 24.3 / UPLR2 (Sept, Nov 2024) |
TCB-R Counter:17 IPU 24.1 (Feb 2024) |
TCB-R Counter:17 IPU 24.1 (Feb 2024) |
TCB-R Counter:17 IPU 24.1 (Feb 2024) |
TCB-R Counter:17 IPU 24.1 (Feb 2024) |
TCB-R Counter:17 IPU 24.1 (Feb 2024) |
||||||||
| 06_6AH | 6 | NA | Ice Lake Xeon-SP | 3rd Gen Intel® Xeon® Scalable processor family |
|
606A6 | 0x433 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | ACM_BIOS | MCU_BIOS_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_6CH | All | NA | Ice Lake Xeon D (Idaville) | Intel® Xeon® D processor family | Embedded | 606C1 | 0x01000301 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | ACM_BIOS | MCU_BIOS_TCBR | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | MCU_BIOS_TCBR | Not Affected |
| 06_7AH | 8 | NA | Gemini Lake |
|
|
706A8 | 0x26 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_BIOS_TCBR (SGX) | Not Affected | Not Affected | Not Affected |
| 06_7EH | 5 | NA | Ice Lake U Ice Lake Y |
10th Generation Intel® Core™ processor family | Mobile | 706E5 | 0xce | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_8EH | C | NA | 1. Whiskey Lake V 2,3,4. Comet Lake U42 5. Amber Lake Y |
|
Mobile | 806EC | 0x100 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_8FH | 5, 6, 7, 8 | CPUID.0x7.EDX[15] =0 | Sapphire Rapids (Golden Cove) |
4th Generation Intel® Xeon® Scalable processors 4th Generation Intel® Xeon® Platinum processors 4th Generation Intel® Xeon® Gold Processors 4th Generation Intel® Xeon® Silver Processor 4th Generation Intel® Xeon®Bronze Processor 4th Gen Intel Xeon Scalable Processors with Intel® vRAN Intel® Xeon® W workstation processors |
Server Workstation Embedded |
806F5, 806F6, 806F7, 806F8 | 2b000685 (SVN6 or above) | SGX_SW4 | TDX_M (1.5.34) | SGX_SW5 | TDX_M (1.5.34) | Not Affected | Not Affected | MCU_BIOS_TCBR | ACM_BIOS (ACTM_EGS_03.00.431) | Not Affected | Not Affected | TDX_M (v1.5.24) |
TDX_M (v1.5.24) |
Not Affected | MCU_BIOS_TCBR | TDX_M (v1.5.16) |
Not Affected | TDX_M (v1.5.16) |
TDX_M (v1.5.16) |
Not Affected | Not Affected | Not Affected | Not Affected | TDX_M | MCU_OSPL_TDX_TCBR MCU_OSPL_SGX_TCBR |
TDX_M | ACM_BIOS | MCU_BIOS_TCBR | ACM_BIOS (TDX) | TDX_M | Not Affected | Not Affected | MCU_BIOS_TCBR | MCU_BIOS_TCBR | MCU_OSPL_SGX_TCBR |
| 06_8FH | 5, 6, 8 | CPUID.0x7.EDX[15] =0 | Sapphire Rapids (Golden Cove) |
Intel® Xeon® CPU Max Series processors (High Bandwidth Memory HBM) | Server | 806F8 | 2c000435 (SVN6 or above) | SGX_SW4 | TDX_M (1.5.34) | SGX_SW5 | TDX_M (1.5.34) | Not Affected | Not Affected | MCU_BIOS_TCBR | ACM_BIOS (ACTM_EGS_03.00.431) | Not Affected | Not Affected | TDX_M (v1.5.24) |
TDX_M (v1.5.24) |
Not Affected | MCU_BIOS_TCBR | TDX_M (v1.5.16) |
Not Affected | TDX_M (v1.5.16) |
TDX_M (v1.5.16) |
Not Affected | Not Affected | Not Affected | Not Affected | TDX_M | MCU_OSPL_TDX_TCBR MCU_OSPL_SGX_TCBR |
TDX_M | ACM_BIOS | MCU_BIOS_TCBR | ACM_BIOS (TDX) | TDX_M | Not Affected | Not Affected | MCU_BIOS_TCBR | MCU_BIOS_TCBR | MCU_OSPL_SGX_TCBR |
| 06_9EH | D | NA |
|
|
|
906ED | 0x104 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_A5H | 2 | NA | Comet Lake H | 10th Generation Intel® Core™ processor family Intel® Xeon® W processor family |
Mobile Workstation |
A0652 | 0x100 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_A5H | 3 | NA | Comet Lake S | 10th Generation Intel® Core™ processor family Intel® Pentium® Gold processor family Intel® Celeron® processor family Intel® Xeon® W processor family |
Desktop Workstation |
A0653 | 0x100 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_A5H | 5 | NA | Comet Lake S | 10th Generation Intel® Core™ processor family Intel® Xeon® W processor family |
Desktop Workstation |
A0655 | 0x100 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_A6H | 0 | NA | Comet Lake U62 | 10th Generation Intel® Core™ processor family | Mobile | A0660 | 0x102 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_A6H | 1 | NA | Comet Lake U62 | Intel® Xeon® W processor family | Desktop | A0661 | 0x100 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_A7H | 1 | NA | Rocket Lake | 1. 11th Generation Intel® Core™ processor family 2. Intel® Xeon® E-2300 processor family 3. Intel® Xeon® W-1300 processor family |
1:Desktop 2: Server 3: Workstation |
A0671 | 0x66 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_AAH | 4 | CPUID.0x7.EDX[15] =1 | Meteor Lake U, H, PS (Redwood Cove, Crestmont) | Intel® Core™ Ultra processor family | Desktop Mobile Embedded |
A06A4 | 0x2a | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_BIOS_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_OSPL_SGX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_ADH | 1 | CPUID.0x7.EDX[15]=0 CPUID.0x1A.EAX[31:24]=40 |
Granite Rapids (Redwood Cove) | Intel® Xeon® Scalable processor family Intel® Xeon® 6 processors |
Server | A06D1 (PID 0x95) | 0x01000434 (SVN7 or above) | SGX_SW4 | TDX_M (2.0.18) | SGX_SW5 | TDX_M (2.0.18) | MCU_BIOS_TCBR | MCU_BIOS_TCBR | MCU_BIOS_TCBR | ACM_BIOS (ACTM_GNR_04.00.432) | Not Affected | Not Affected | TDX_M (2.0.14) |
TDX_M (2.0.14) |
MCU_BIOS_TCBR | MCU_BIOS_TCBR | TDX_M (v2.0.08) |
MCU_OSPL_TDX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_ADH | 1 | CPUID.0x7.EDX[15]=0 CPUID.0x1A.EAX[31:24]=40 |
Granite Rapids (Redwood Cove) | Intel® Xeon® 600 processors | Workstation | A06D1 (PID 0x02) | 0x01000202 (SVN7 or above) | SGX_SW4 | TDX_M (2.0.18) | SGX_SW5 | TDX_M (2.0.18) | MCU_BIOS_TCBR | MCU_BIOS_TCBR | MCU_BIOS_TCBR | ACM_BIOS (ACTM_GNR_04.00.432) | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_ADH | 0,1 | CPUID.0x7.EDX[15] =0 CPUID.0x1A.EAX[31:24] = 40 | Granite Rapids R1S (Redwood Cove) | Intel® Xeon® 6741P,6781P,6761P, 6731P, 6511P, 6774P processors | Server | A06D1 (PID 0x20) | 0x0A000151 (SVN7 or above) | SGX_SW4 | TDX_M (2.0.18) | SGX_SW5 | TDX_M (2.0.18) | MCU_BIOS_TCBR | MCU_BIOS_TCBR | MCU_BIOS_TCBR | ACM_BIOS (ACTM_GNR_04.00.432) | Not Affected | Not Affected | TDX_M (v2.0.14) |
TDX_M (v2.0.14) |
MCU_BIOS_TCBR | MCU_BIOS_TCBR | TDX_M (v2.0.08) |
MCU_OSPL_TDX_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_AEH | 1 | CPUID.0x7.EDX[15] =0 CPUID.0x1A.EAX[31:24] = 40 | Granite Rapids-D (Redwood Cove) | Intel® Xeon® 6700P-B/6500P-B Series P-cores | Embedded | A06E1 | 0x01000309 (SVN7 or above) | SGX_SW4 | TDX_M (2.0.18) | SGX_SW5 | TDX_M (2.0.18) | MCU_BIOS_TCBR | MCU_BIOS_TCBR | MCU_BIOS_TCBR | ACM_BIOS (ACTM_GNRD_04.00.430) | Not Affected | Not Affected | TDX_M (v2.0.14) |
TDX_M (v2.0.14) |
Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_AFH | 3 | CPUID.0x7.EDX[15] =0 CPUID.0x1A.EAX[31:24] = 20 | Sierra Forest (Crestmont) | Intel® Xeon® 6 processor family | Server | A06F3 | 0x030003B2 (SVN7 or above) | SGX_SW4 | Not Affected | SGX_SW5 | TDX_M (1.5.34) | MCU_BIOS_TCBR | Not Affected | MCU_BIOS_TCBR | ACM_BIOS (ACTM_SRF_04.00.433) | Not Affected | Not Affected | TDX_M (1.5.25) |
TDX_M (1.5.25) |
MCU_BIOS_TCBR | MCU_BIOS_TCBR | TDX_M (1.5.16) |
Not Affected | TDX_M (1.5.16) |
TDX_M (1.5.16) |
Not Affected | MCU_OSPL_TDX_TCBR | MCU_BIOS_TCBR | ACM_BIOS | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_B5 | 0 | CPUID.0x7.EDX[15] =1 | Arrow Lake U (Redwood Cove, Crestmont) | Intel® Core™ Ultra 5, 7, 9 processor families Intel® Core™ Ultra 200 U |
Mobile | B0650 | 0x0e | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_BIOS_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_BD | 1 | CPUID.0x7.EDX[15] =1 | Lunar Lake (Lion Cove, Skymont) | Intel® Core™ Ultra 5, 7, 9 processor families | Mobile | B06D1 | 0x128 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_BIOS_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_C5H | 2 | CPUID.0x7.EDX[15] =1 | Arrow Lake H (Lion Cove, Skymont) | Intel® Core™ Ultra 5, 7, 9 processor families | Desktop | C0652 | 0x122 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_BIOS_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_C6H | 2 | CPUID.0x7.EDX[15] =1 | Arrow Lake H/HX/S/S Plus (Lion Cove, Skymont) | Intel® Core™ Ultra 5, 7, 9 processor families Intel® Core™ Ultra 200 Plus Series Intel® Core™ Ultra 200 Series |
Desktop Mobile |
C0662 | 0x122 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_BIOS_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_CFH | 1, 2 | CPUID.0x7.EDX[15] =0 CPUID.0x1A.EAX[31:24] = 40 | Emerald Rapids (Raptor Cove) | 5th Generation Intel® Xeon® Scalable processors | Server | C06F2 | 210002f4 | SGX_SW4 | TDX_M (1.5.34) | SGX_SW5 | TDX_M (1.5.34) | Not Affected | Not Affected | MCU_BIOS_TCBR | ACM_BIOS (ACTM_EGS_03.00.431) | Not Affected | Not Affected | TDX_M (v1.5.24) |
TDX_M (v1.5.24) |
Not Affected | MCU_BIOS_TCBR | TDX_M (1.5.16) |
Not Affected | TDX_M (1.5.16) |
TDX_M (1.5.16) |
Not Affected | Not Affected | Not Affected | Not Affected | TDX_M | MCU_OSPL_TDX_TCBR MCU_OSPL_SGX_TCBR |
TDX_M | ACM_BIOS | MCU_BIOS_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_CCH | 2, 3 | CPUID.0x7.EDX[15] =1 | Panther Lake (Cougar Cove, Darkmont) | Intel® Core™ Ultra Series 3 processors | Mobile | C06C2 C06C3 |
0x0000011c | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | MCU_BIOS_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
| 06_D7H | 0 | CPUID.0x7.EDX[15] =0 CPUID.0x1A.EAX[31:24] = 40 | Bartlett Lake (Raptor Cove) | Intel® Core™ 200 processors | Server | D0670 | 0x00000137 | SGX_SW4 | Not Affected | SGX_SW5 | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | TDX_M (v1.5.24) |
TDX_M (v1.5.24) |
Not Affected | MCU_BIOS_TCBR | TDX_M (1.5.16) |
Not Affected | TDX_M (1.5.16) |
TDX_M (1.5.16) |
Not Affected | Not Affected | Not Affected | Not Affected | TDX_M | MCU_OSPL_TDX_TCBR MCU_OSPL_SGX_TCBR |
TDX_M | ACM_BIOS | MCU_BIOS_TCBR | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected | Not Affected |
Key
MCU: Mitigation requires a microcode update. It is runtime effective.
MCU_BIOS_TCBR: Mitigation requires an updated BIOS carrying new microcode only loadable in flash to be reflected in Intel SGX and Intel TDX attestation and TCB-R completion.
MCU_OSPL_SGX_TCBR: Mitigation eligible for Intel SGX runtime update. After OS Patch Loading (OSPL), tear down all enclaves, perform EUPDATESVN, and then relaunch any enclave. The new microcode update will be attestable and TCB-R will be complete. No further action is required for non-Intel SGX.
If the operating system enabling for the runtime update is not available, that is, EUPDATESVN is not supported by the operating system, attestation is possible with a warm reset. After a warm reset, and if OSPL is done prior to the loading of the first enclave, then neither EUPDATESVN support nor MCU_BIOS update is required.
If the above options are not feasible, treat this as MCU_BIOS_TCBR. For more information, see Microcode Update Guidance.
MCU_OSPL_TDX_TCBR: Mitigation eligible for Intel TDX runtime update. A new microcode update will be attestable. No further action is required for non-Intel TDX.
If the operating system enabling for the runtime update is not available, that is, TDPRESERVING is not supported by the virtual machine monitor (VMM), attestation is possible with a warm reset. After a warm reset, and if OSPL is done prior to the loading of the first enclave, then neither TDPRESERVING support nor MCU_BIOS update is required.
If the above options are not feasible, treat this as MCU_BIOS_TCBR. For more information, see Microcode Update Guidance.
ACM_BIOS: Mitigation requires an Authenticated Code Module (ACM) update, which is part of a BIOS update. A BIOS update and cold reset are required.
ACM_SINIT: Mitigation requires an update to Intel® Trusted Execution Technology, which can be updated at runtime for effectiveness, and is applicable to a VMM or host operating system. All virtual machines (VM) will be lost. A cold reset is required for attestation and complete TCB-R.
TDX_M: Mitigation requires an Intel TDX module update.
If TDPRESERVING is supported by the VMM, mitigation is eligible for an Intel TDX module runtime update. This new Intel TDX module update will be attestable. No further action is required for non-Intel TDX.
If TDPRESERVING is not supported by the VMM:
If the VMM/OS supports loading the TDX Module upon boot, a warm reset is required for attestation. After a warm reset, the VMM loads the new Intel TDX module to complete TCB-R.
If the VMM/OS does not support loading the TDX Module, you will need to use BIOS to update the TDX Module (See the Intel TDX Module BIOS Install document)
Either go to the OEM/ODM that provides the IFWI to update the Intel TDX Module to the required version, or put the required TDX Module in the EFI System Partition (ESP) to allow existing IFWI to load the new Intel TDX Module.
SGX_E: Mitigation requires updating and reloading an Intel SGX architectural enclave. A warm reset is not necessary for attestability and TCB-R completion.
SGX_SW: Mitigation required updating and reloading Intel SGX software collection (for example, Intel® Data Center Attestation Primitives (Intel® DCAP)) required for attestation.
Not Affected: Products are not affected or mitigated through hardware and may not be enumerated.
No Planned Mitigation: An issue exists but no mitigation is planned.
Recent TCB-R Public Disclosure Dates
On the date of every Trusted Computing Base Recovery (TCB-R) public disclosure, Intel publishes new Security Advisories (INTEL-SA), Provisioning Certification Key (PCK) certificates, and verification collateral. For more details about verification collateral, refer to the next section. For more information about TCB-Rs, refer to the Trusted Computing Base Recovery article.
Dates of recent TCB-R public disclosures:
Provisioning Certification Service (PCS) Verification Collateral Availability
To verify Intel SGX or Intel TDX quotes, the Provisioning Certification Service (PCS) offers multiple API endpoints to download corresponding verification collateral. The following PCS API endpoints support optional parameters to retrieve specific collateral:
- Get Intel® SGX TCB Info: https://api.trustedservices.intel.com/sgx/certification/v4/tcb
- Get Intel® TDX TCB Info: https://api.trustedservices.intel.com/tdx/certification/v4/tcb
- Get Intel® SGX QE Identity: https://api.trustedservices.intel.com/sgx/certification/v4/qe/identity
- Get TDQE Identity: https://api.trustedservices.intel.com/tdx/certification/v4/qe/identity
- Get QvE Identity: https://api.trustedservices.intel.com/sgx/certification/v4/qve/identity
- Get QaE Identity: https://api.trustedservices.intel.com/sgx/certification/v4/qae/identity
The optional parameters for these endpoints are:
- update: Can be defined as early or standard, or left undefined:
- update=early: The endpoints return the collateral corresponding to the latest TCB-R public disclosure (see the "Recent TCB-R Public Disclosure Dates" section). At any given time, the endpoints return collateral corresponding to only one TCB-R.
The "Early" row of Figure 1 shows the exact start and end dates of when Intel® PCS provides verification collateral for each TCB-R.
Collateral corresponding to TCB-R 22 is returned starting August 11, 2026. - update=standard or undefined: The endpoints return collateral corresponding to a specific TCB-R at a defined interval after it is first published using update=early. Unless otherwise specified, this interval is approximately 12 months. At any given time, the endpoints return collateral corresponding to only one TCB-R.
The "Standard" row of Figure 1 shows the start and end dates of when Intel® PCS provides verification collateral for each TCB-R.
Collateral corresponding to TCB-R 20 is returned starting August 12, 2026, and collateral corresponding to TCB-R 21 will be returned starting February 10, 2027.
- update=early: The endpoints return the collateral corresponding to the latest TCB-R public disclosure (see the "Recent TCB-R Public Disclosure Dates" section). At any given time, the endpoints return collateral corresponding to only one TCB-R.
- tcbEvaluationDataNumber: Can be left undefined or set to a specific <TCB-R Counter>:
- tcbEvaluationDataNumber undefined: No influence on the returned collateral.
- tcbEvaluationDataNumber=<TCB-R Counter>: The endpoints return collateral corresponding to the defined <TCB-R Counter>. The <TCB-R Counter> values are only valid if they fall between the TCB-R versions currently returned by update=standard and update=early (inclusive).
- To determine valid counters, locate today's date along the timeline in Figure 1. The TCB-R presented in the "Standard" row defines the minimum valid <TCB-R Counter>, and the TCB-R presented in the "Early" row defines the maximum valid <TCB-R Counter>.
- Starting August 12, 2026, the following TCB-R Counters are valid: 20, 21, and 22. From February 10, 2027, the TCB-R Counter 20 can no longer be used.
Notes:
- For more detailed information on the Intel PCS APIs, please see the Intel PCS API documentation.
- The update and tcbEvaluationDataNumber parameters cannot be used in the same request.
- The end date of the latest TCB-R is defined by the announcement of the next TCB-R and thus considered as TBD.
- Unless otherwise specified, Intel PCS updates are targeted around 11 PM PT (Pacific Time) at the listed date.
Figure 1. Verification collateral returned by Intel PCS based on date and update parameter. Red means that collateral is no longer available, green means that collateral is currently returned, and yellow means that collateral will be provided.
Action Required
The Intel® platform update guidance document typically contains mitigation updates for Intel SGX and Intel TDX. For TCB-R 21, only Intel TDX is in scope. The Best-Known Configuration (BKC) kit for each processor is under the IPU Update Guidance tab, in the IPU Kit column.
Customers under non-disclosure agreements (NDA) with Intel looking for specific Resource and Documentation Center (RDC) numbers can refer to the guidance documents in the Intel platform update collection.
| Action Required | TCB-R 22 | TCB-R 21 | TCB-R 20 |
|---|---|---|---|
Platforms with Intel TDX |
|
Mitigation requires an Intel TDX module update. When TDPRESERVING is supported by the VMM, mitigation is eligible for an Intel TDX module runtime update. This new Intel TDX module update will be attestable. If TDPRESERVING is not supported by the VMM, a warm reset is required for attestation. After a warm reset, the VMM loads the new Intel TDX module to complete TCB-R. |
Obtain the latest BIOS for your product from your original equipment manufacturer (OEM) and original device manufacturer (ODM) if OSPL is not effective. If OSPL is effective, download the MCU from Intel. Ensure that it has the components shown in the following list:
|
| Platforms with Intel SGX |
|
|
Obtain the latest BIOS for your product from your original equipment manufacturer (OEM) or original device manufacturer (ODM) if OSPL is not effective. If OSPL is effective, download the MCU from Intel. For both Intel TDX and Intel SGX, use the MCU version as reflected in TCB-R table or later. Follow all prior Best-Known Configuration Guidance for published mitigations. |
Platforms using Intel SGX / Intel TDX software |
|
|
|
Software using Intel SGX |
|
||
Enabling Quote Generation |
If you own or control the infrastructure:
If you do not own or control the infrastructure:
|
|
If you own or control the infrastructure:
If you do not own or control the infrastructure:
|
Enabling Quote Verification |
If you own or control the infrastructure:
If you do not own or control the infrastructure:
|
If you own or control the infrastructure:
If you do not own or control the infrastructure:
|
If you own or control the infrastructure:
If you do not own or control the infrastructure:
|
Update on Errata (TCB-R 20)
The Intel DCAP release v1.24 released in late Q4, 2025 contains a fix for this issue as reported. The latest version can be downloaded here.
Prior Updates: The TCB-R 20, initiated August 12, 2025 (for update = “early”) continues to be affected by the issue first identified with TCB-R 18 with Intel® Software Guard Extensions ECDSA Quote Verification Library: the list of advisory IDs (commonly known as the Security Advisory List) reported by the library may not be complete. In more detail, Advisory IDs assigned to Intel TDX module identity may be missing. As a reminder, the issue does not affect the accuracy of the tcbStatus (that is, UpToDate, OutOfDate) or the tcbDate value reported by the library. Instead, only the completeness of the advisory IDs list is affected. Intel has implemented a workaround to this issue in certain instances of the verification collateral (TCB Info) returned by the Intel Provisioning Certification Service. Click on the applicable link to view details: TCB-R 20 QVL forum post.
Attestation Appraisal
Intel SGX and Intel TDX developers rely on attestation verification responses to make security-sensitive operational decisions. However, developer requirements may vary depending on risk tolerance, workload characteristics, operational environments, and other factors. To support these diverse needs, Intel provides several software options that offer enhanced attestation appraisal capabilities. These options help evaluate Intel SGX and Intel TDX platforms before, during, and after platform updates or Intel public disclosures, while also allowing infrastructure providers and customers to enforce their own trust policies and tolerances.
- Intel® Tiber™ Trust Authority
- Trusted Components for Attestation and Secret Management (Trustee), part of Confidential Containers
- The Intel® DCAP software packages below provide attestation appraisal source code, samples, and documentation:
- Intel DCAP on GitHub
- Appraisal Engine sample (located in the Intel DCAP software branch)
- Appraisal Engine Developer Guide
Footnotes
- CPUID description: Example CPUID = 906EB. Family = 06 / Extended Model = 9 / Model Number = E / Stepping ID = B. See Intel Software Developer’s Manual Version 071, Volume 2A, Figure 3-6 for reference.
- Intel recommends ensuring all security mitigations provided by Intel are applied and systems are running the latest firmware/MCU versions available. MCU updates may still be required for enumeration even when processors are not affected. Contact OS/VMM vendors for the latest software updates.
Linux users: The microcode image is named after the family/model/stepping. You can locate these from /proc/cpuinfo. Example: For Family 06, Model 85, Stepping 4 (values in decimal), the corresponding microcode file is 06-55-04 located in /lib/firmware/intel-ucode/ (values in hexadecimal)."
Look at the microcode version number at the official public Intel microcode website. Calculate Family-Model-Stepping before downloading appropriate microcode.
Windows users: Read the version with the following PowerShell command: reg query HKLM\HARDWARE\DESCRIPTION\System\CentralProcessor\0 /v "Update Revision"
Or use the Intel® Processor Identification Utility tool to check the microcode version and compare it against the latest microcode listed above.
For more information, see:
- This product has reached its End of Servicing Update (ESU) date. Please see our Support webpage for further information. For customers interested in extending updates beyond ESU, please contact your Intel representative for details.
- Intel® Data Center Attestation Primitives (Intel® DCAP) v1.2 to v1.24 impacted, update to Intel DCAP v1.25
- Intel DCAP v1.14 to 1.23 impacted, update to Intel DCAP v1.24