The principle for TEE OS is to keep it minimal and clean.
Copy Fail (CVE-2026-31431) is nasty.
But dstack is not affected.
I checked our TDX host today: the vulnerable AF_ALG/algif_aead path simply isn’t there.
This is a good reminder for TEE builders: what you don’t ship matters.
x.com/brian_pak/stat…







