GPU VulnDB

Database/Firmware, BMC & network fabric

Intel SGX SDK (asynchronous exit / exception handling): MULTI-TENANT ISOLATION: SmashEx: an asynchronous exception

CVE-2021-0186Firmware, BMC & network fabricSmashExcurated

Impact

MULTI-TENANT ISOLATION: SmashEx: an asynchronous exception delivered at the right moment during an enclave entry/exit leaves the enclave's internal state inconsistent, and the SDK's own exception handling can then be steered into an in-enclave control-flow hijack. Because the host controls interrupt delivery, the attacker in this model is the platform - so it is a direct break of the confidential-compute promise, and it recovers enclave secrets in the published attack.

Who can reach it

Privileged host code that can inject exceptions/interrupts into a running enclave - i.e. the hypervisor or host OS on a confidential-compute node.

What to do

Rebuild enclaves against a fixed SGX SDK and re-attest. This is a software fix in the SDK's AEX handling, so it needs a new enclave binary from the enclave author; no microcode, BIOS or reboot on the operator side, but also nothing the operator can do alone.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.