Database/Firmware, BMC & network fabric
Intel SGX driver for Linux: Insufficient input validation in the out-of-tree SGX Linux driver lets a local
CVSS 5.5CVE-2019-0157Firmware, BMC & network fabriccurated
Impact
Insufficient input validation in the out-of-tree SGX Linux driver lets a local authenticated user deny service. Relevant on hosts still running the legacy Intel SGX DKMS driver rather than the in-kernel driver.
Who can reach it
Local authenticated user with access to the SGX device node.
What to do
Move to the in-kernel SGX driver where the kernel supports it, otherwise update the Intel SGX DKMS driver. Driver reload or reboot; no firmware or microcode.
References
Related entries
- Intel PTT / fTPM (ECDSA and ECSchnorr timing): The firmware TPM's signing operation leaks nonce information throughCVE-2019-11090 · Intel PTT / fTPM (ECDSA and ECSchnorr timing)Medium
- Linux bnxt_re RoCE driver (bnxt_re_create_srq memory leak): A tenant can exhaust host memory by repeatedly triggeringCVE-2019-19077 · Linux bnxt_re RoCE driver (bnxt_re_create_srq memory leak)Medium
- Intel processors (vector register sampling): Stale values left in vector registers can be sampled by other contextsCVE-2020-0548 · Intel processors (vector register sampling)Medium
- Intel processors (L1D eviction sampling) / SGX attestation keys: Stale data can be sampled out of L1D fill buffersCVE-2020-0549 · Intel processors (L1D eviction sampling) / SGX attestation keysMedium
- AMD EPYC SEV-ES / SEV-SNP - information disclosure: An information-disclosure flaw in SEV-ES and SEV-SNP on EPYC lets aCVE-2020-12966 · AMD EPYC SEV-ES / SEV-SNP - information disclosureMedium
- Intel processors (fast store forwarding predictor): Improper isolation of a shared microarchitectural resource letsCVE-2020-8698 · Intel processors (fast store forwarding predictor)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.