GPU VulnDB

Database/Firmware, BMC & network fabric

Intel SGX SDK: Insufficient initialisation in the SGX SDK means enclaves built with the affected SDK can leak

CVE-2019-14565Firmware, BMC & network fabriccurated

Impact

Insufficient initialisation in the SGX SDK means enclaves built with the affected SDK can leak uninitialised memory or be pushed into privilege escalation. The fix has to be applied by whoever builds the enclave, which for an operator means chasing your confidential-compute vendors rather than patching your own fleet.

Who can reach it

Local authenticated user interacting with an enclave built against a vulnerable SDK.

What to do

Rebuild enclaves against SGX SDK 2.5 (Windows) / 2.7 (Linux) or later. Not an operator-side patch: it requires a new enclave binary from the software vendor, a re-signed enclave, and re-attestation. No node reboot.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.