PT-2023-26248 · Fortanix+1 · Fortanix Enclaveos Confidential Computing Manager (Ccm) Platform+1

CVE-2023-38021

·

Publicado

2023-12-29

·

Atualizado

2024-01-17

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform versions prior to 3.32 for Intel SGX
Description An issue was discovered in the Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform, which relates to a lack of pointer-alignment validation logic in entry functions. This allows a local attacker to access unauthorized information, specifically through the enclave ecall function and system call layer.
Recommendations For versions prior to 3.32, update to version 3.32 or later to resolve the issue. As a temporary workaround, consider restricting access to the enclave ecall function until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-38021
GHSA-V3VM-9H66-WM76

Produtos afetados

Fortanix Enclaveos Confidential Computing Manager (Ccm) Platform
Intel Sgx