Database/Firmware, BMC & network fabric
Intel SGX SDK (Edger8r generated code, side channel): Edger8r generated bridge code that was susceptible to a side
CVSS 4.7CVE-2018-3626Firmware, BMC & network fabriccurated
Impact
Edger8r generated bridge code that was susceptible to a side channel, so a local user could recover information crossing the enclave boundary. Earliest member of the generated-bridge-code family.
Who can reach it
Local user interacting with a vulnerable enclave.
What to do
Rebuild enclaves with SGX SDK 2.1.2 (Linux) / 1.9.6 (Windows) or later and re-attest.
References
Related entries
- AMD processors - PREFETCH instruction timing and power side channel: Timing and power measurements around the x86CVE-2021-26318 · AMD processors - PREFETCH instruction timing and power side channelMedium
- AMD processors with SMT - speculative execution across SMT mode switch: With SMT enabled, certain AMD processorsCVE-2022-27672 · AMD processors with SMT - speculative execution across SMT mode switchMedium
- Intel processors (return stack buffer alternate prediction): When the return stack buffer underflows, the processorCVE-2022-28693 · Intel processors (return stack buffer alternate prediction)Medium
- AMD processors - power side channel on cache line data changes: An authenticated attacker who can read CPU powerCVE-2023-20583 · AMD processors - power side channel on cache line data changesMedium
- Linux kernel (drivers/vfio/pci/mlx5): Pages allocated for a device migration buffer are not freed when adding them toCVE-2024-56742 · Linux kernel (drivers/vfio/pci/mlx5)Medium
- Intel / Solidigm SSD, SSD DC and Optane SSD firmwareCVE-2021-33082 · Intel / Solidigm SSD, SSD DC and Optane SSD firmware - NVMe Sanitize (Block Erase) leaves prior data recoverableMedium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.