Database/Firmware, BMC & network fabric
Intel processors / SGX (load value injection): The inverse of Meltdown: instead of leaking data out of the enclave, the
Impact
The inverse of Meltdown: instead of leaking data out of the enclave, the attacker injects a value into a faulting load inside the victim enclave and steers its transient execution into attacker-chosen gadgets. That gives enclave-secret extraction from outside the enclave, again breaking the SGX guarantee against a privileged host.
Who can reach it
Local privileged code on the host targeting a victim enclave on the same machine.
What to do
SGX SDK/PSW update that inserts LFENCE serialisation in enclave code, plus microcode. The software mitigation requires recompiling enclaves with the patched SDK - a code change for whoever ships the enclave, not something the operator can apply unilaterally - and it carries a heavy performance cost. Microcode is late-loadable at boot; enclave recompilation is not. Re-attestation required.
References
Related entries
- AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715): The LFENCE/JMP sequence AMD originallyCVE-2021-26401 · AMD processors - LFENCE/JMP mitigation for Spectre v2 (CVE-2017-5715)Medium
- Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-ACVE-2022-23960 · Arm Cortex-A and Neoverse cores (Neoverse N1/N2/V1 among them); Trusted Firmware-A; also tracked by Ampere as…Medium
- Intel irdma driver (Ethernet Controller RDMA for Linux): Improper access control in the Intel RDMA driver lets anCVE-2023-25775 · Intel irdma driver (Ethernet Controller RDMA for Linux)Medium
- Intel TDX module: An out-of-bounds read in the TDX module reachable by an authenticated user, leaking informationCVE-2024-33607 · Intel TDX moduleMedium
- Intel Atom processors (shared predictor transient execution): Shared microarchitectural predictor state influencesCVE-2024-43420 · Intel Atom processors (shared predictor transient execution)Medium
- Intel processors (indirect branch predictor race): Branch Privilege Injection: a race in how the indirect branchCVE-2024-45332 · Intel processors (indirect branch predictor race)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.