Database/Firmware, BMC & network fabric
Intel SGX SDK: Insufficient initialisation in the SGX SDK means enclaves built with the affected SDK can leak
Impact
Insufficient initialisation in the SGX SDK means enclaves built with the affected SDK can leak uninitialised memory or be pushed into privilege escalation. The fix has to be applied by whoever builds the enclave, which for an operator means chasing your confidential-compute vendors rather than patching your own fleet.
Who can reach it
Local authenticated user interacting with an enclave built against a vulnerable SDK.
What to do
Rebuild enclaves against SGX SDK 2.5 (Windows) / 2.7 (Linux) or later. Not an operator-side patch: it requires a new enclave binary from the software vendor, a re-signed enclave, and re-attestation. No node reboot.
References
Related entries
- Intel SGX SDK: Insufficient input validation in the SGX SDK's generated edge routines, letting a local userCVE-2019-14566 · Intel SGX SDKHigh
- Intel SGX SDK (< 2.6.100.1): Improper initialisation in the SGX SDK gives an authenticated local user a privilegeCVE-2020-0561 · Intel SGX SDK (< 2.6.100.1)High
- AMD PSP trusted applications shipped in the AMD Graphics Driver: Trusted applications bundled with the AMD graphicsCVE-2020-12929 · AMD PSP trusted applications shipped in the AMD Graphics DriverHigh
- AMD Secure Processor (ASP) drivers: Improper parameter handling in the ASP driver layer lets an already-privilegedCVE-2020-12930 · AMD Secure Processor (ASP) driversHigh
- AMD Secure Processor (ASP) kernel: Improper parameter handling in the ASP's own kernel gives a privileged attackerCVE-2020-12931 · AMD Secure Processor (ASP) kernelHigh
- AMD PSP - System Management Network privileged register zeroing: An attacker can zero any privileged register on theCVE-2020-12961 · AMD PSP - System Management Network privileged register zeroingHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.