Database/Firmware, BMC & network fabric
Intel SGX SDK (asynchronous exit / exception handling): SmashEx: an asynchronous exception delivered at the right
Impact
SmashEx: an asynchronous exception delivered at the right moment during an enclave entry/exit leaves the enclave's internal state inconsistent, and the SDK's own exception handling can then be steered into an in-enclave control-flow hijack. Because the host controls interrupt delivery, the attacker in this model is the platform - so it is a direct break of the confidential-compute promise, and it recovers enclave secrets in the published attack.
Who can reach it
Privileged host code that can inject exceptions/interrupts into a running enclave - i.e. the hypervisor or host OS on a confidential-compute node.
What to do
Rebuild enclaves against a fixed SGX SDK and re-attest. This is a software fix in the SDK's AEX handling, so it needs a new enclave binary from the enclave author; no microcode, BIOS or reboot on the operator side, but also nothing the operator can do alone.
References
Related entries
- GRUB2 (short-form option parser): Heap out-of-bounds write in the short-form option parserCVE-2021-20225 · GRUB2 (short-form option parser)Medium
- GRUB2 (option quoting): Miscalculated buffer size when quoting options produces a heap out-of-bounds writeCVE-2021-20233 · GRUB2 (option quoting)Medium
- InsydeH2O: mishandled PlatformLangCodes UEFI variable overflows a buffer and exhausts firmware resourcesCVE-2021-43614 · Insyde InsydeH2O (PlatformLangCodes UEFI variable handling)Medium
- GRUB2 (chainloader): Use-after-free in grub_cmd_chainloader when a chainloaded image fails to startCVE-2022-28736 · GRUB2 (chainloader)Medium
- CryptoPro Secure Disk (signed UEFI bootloader): A Microsoft-signed bootloader that can be made to execute arbitraryCVE-2022-34301 · CryptoPro Secure Disk (signed UEFI bootloader)Medium
- New Horizon Datasys (signed UEFI bootloader): Signed bootloader with a built-in mechanism to bypass Secure BootCVE-2022-34302 · New Horizon Datasys (signed UEFI bootloader)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.