Database/Firmware, BMC & network fabric
Intel SGX DCAP (datacenter attestation primitives): An improper conditions check in DCAP lets an unauthenticated
Impact
An improper conditions check in DCAP lets an unauthenticated adjacent attacker deny service to the attestation path. In a confidential-compute fleet, killing attestation means new workloads cannot start and existing ones cannot renew - an availability failure that looks like a control-plane outage.
Who can reach it
Unauthenticated attacker with adjacent network access to the attestation service - so anything on the same network segment as your PCCS/quote-generation service.
What to do
Upgrade SGX DCAP to 1.6 or later and keep the caching service off flat networks. Userspace service update and restart; no node reboot or firmware.
References
Related entries
- Intel Ethernet 800 Series Controller firmware: Out-of-bounds read in 800-series (E810 family) adapter firmwareCVE-2021-0009 · Intel Ethernet 800 Series Controller firmwareMedium
- AMD processors - transient execution beyond unconditional direct branches: Some AMD CPUs transiently executeCVE-2021-26341 · AMD processors - transient execution beyond unconditional direct branchesMedium
- InsydeH2O: BIOS user and administrator password hashes exposed in runtime-readable UEFI variablesCVE-2021-43613 · Insyde InsydeH2O SysPasswordDxe (BIOS password hashes in runtime UEFI variables)Medium
- Lanner IAC-AST2500A BMC firmware: The attacker rewrites who is permitted to use KVM and virtual media on the BMCCVE-2021-44776 · Lanner IAC-AST2500A BMC firmwareMedium
- AMD SEV / SEV-ES / SEV-SNP - ciphertext observability: SEV encrypts guest memory deterministically per physicalCVE-2021-46744 · AMD SEV / SEV-ES / SEV-SNP - ciphertext observabilityMedium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en): The transmit health reporter's dump callback casts itsCVE-2021-46931 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.