Database/Firmware, BMC & network fabric
Intel SGX (L1 terminal fault on enclave pages): Speculative execution lets code outside an enclave read the enclave's
Impact
Speculative execution lets code outside an enclave read the enclave's data out of the L1 data cache, breaking the confidentiality guarantee SGX exists to provide. On a confidential-compute offering this is the whole product failing: the host, or a co-resident tenant with the right sibling-thread placement, reads enclave secrets including sealing and attestation material.
Who can reach it
Local code execution on the same physical core as the enclave. In a cloud that includes a co-tenant on a sibling hyperthread, which is why the mitigation story involves disabling SMT.
What to do
Microcode update plus OS/hypervisor mitigations. Intel microcode for this can be late-loaded at boot by the OS without waiting for an OEM BIOS release, so the practical path is: update the microcode package, reboot, and disable SMT (or enforce core scheduling) on nodes that run untrusted co-tenants. Also re-attest and re-provision any enclave secrets that existed on unpatched hardware - the microcode fix does not un-leak them.
References
Related entries
- AMD Secure Processor Secure OS - memory buffer checking: A malicious trusted application can read and write the ASPCVE-2022-23817 · AMD Secure Processor Secure OS - memory buffer checkingHigh
- Lenovo XClarity Controller (XCC) - LDAP/AD authorization: When XCC is configured to authenticate against ActiveCVE-2023-29057 · Lenovo XClarity Controller (XCC) - LDAP/AD authorizationHigh
- BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmwareCVE-2023-29164 · BMC firmware for Intel Server Boards S2600WF / S2600ST / S2600BP before 02.01.0017 and M50CYP, and OpenBMC firmware…High
- Linux bnxt_en driver (bnxt_fill_hw_rss_tbl): Memory out-of-bounds in the RSS indirection-table path of the Broadcom NICCVE-2024-44933 · Linux bnxt_en driver (bnxt_fill_hw_rss_tbl)High
- Linux kernel mpi3mr driver (Broadcom tri-mode 9600-series HBA/RAID) and megaraid_sas driver: Rapidly toggling PHYCVE-2024-57804 · Linux kernel mpi3mr driver (Broadcom tri-mode 9600-series HBA/RAID) and megaraid_sas driverHigh
- BullSequana XH3406/XH3515 BMC: factory reset can leave root enabled with no passwordCVE-2025-15679 · BullSequana XH3406 / XH3515 BMC (root account after factory reset)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.