Database/Firmware, BMC & network fabric
Intel SGX Linux kernel driver: Uncontrolled resource consumption in the in-kernel SGX driver lets a local authenticated
CVSS 5.5CVE-2021-33135Firmware, BMC & network fabriccurated
Impact
Uncontrolled resource consumption in the in-kernel SGX driver lets a local authenticated user exhaust EPC or driver resources and deny SGX to everyone else on the node.
Who can reach it
Local authenticated user with SGX device access - on a confidential-compute node, any tenant.
What to do
Kernel update and reboot. Kernel-only, no firmware.
References
Related entries
- Linux kernel RDMA core (UVERBS_METHOD_QUERY_GID_TABLE): The GID-table query handler used a user-supplied entry sizeCVE-2021-47080 · Linux kernel RDMA core (UVERBS_METHOD_QUERY_GID_TABLE)Medium
- Linux KVM SEV API - host kernel crash from unprivileged guest creation: A non-root host user-level application canCVE-2022-0171 · Linux KVM SEV API - host kernel crash from unprivileged guest creationMedium
- Intel processors (shared buffers data sampling): Incomplete cleanup of microarchitectural fill buffers lets a localCVE-2022-21125 · Intel processors (shared buffers data sampling)Medium
- Intel processors (post-barrier return stack buffer): PBRSB: return predictions made after an IBPB barrier can still useCVE-2022-26373 · Intel processors (post-barrier return stack buffer)Medium
- Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63: A local low-privilege actor gains write accessCVE-2022-43309 · Supermicro X11SSL-CF hardware revision 1.01, BMC firmware v1.63Medium
- Linux kernel (drivers/infiniband/sw/rxe): Any tenant that can open an RDMA verbs device can oops the node. A queue-pairCVE-2022-50127 · Linux kernel (drivers/infiniband/sw/rxe)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.