Database/Firmware, BMC & network fabric
Intel Xeon memory controller configuration (with SGX): Memory controller configuration registers are left with
Impact
Memory controller configuration registers are left with permissions that let a privileged local user reach a privilege escalation on SGX-enabled Xeon platforms. Memory controller configuration is the layer that enforces where enclave memory lives, so getting it wrong is structurally worse than a normal ring-0 bug on a confidential-compute host.
Who can reach it
Privileged local access on the host.
What to do
Platform BIOS/firmware update from the OEM, plus TCB recovery and re-attestation. BIOS means a per-node drain, a reboot, and waiting on OEM packaging - budget quarters, not weeks, on server boards.
References
Related entries
- Intel Xeon memory controller configuration (with SGX): Incorrect default permissions on Xeon memory controllerCVE-2024-21820 · Intel Xeon memory controller configuration (with SGX)High
- Intel Xeon memory controller configuration (with SGX): An improper conditions check in Xeon memory controllerCVE-2024-23918 · Intel Xeon memory controller configuration (with SGX)High
- Intel Xeon processors (SGX/TDX error injection): Unauthorised error injection against SGX or TDX on affected Xeon partsCVE-2022-41804 · Intel Xeon processors (SGX/TDX error injection)High
- NVIDIA DGX BMC (AMI-derived management controller): The BMC's SPX REST API lets an authorised attacker read and writeCVE-2022-42278 · NVIDIA DGX BMC (AMI-derived management controller)High
- NVIDIA DGX BMC (AMI-derived management controller): The DGX-1 BMC's SPX REST API accepts injected shell commandsCVE-2023-25507 · NVIDIA DGX BMC (AMI-derived management controller)High
- AMD Power Management Firmware (PMFW) - unintended proxy to the System Management Unit: The GPU power managementCVE-2023-31313 · AMD Power Management Firmware (PMFW) - unintended proxy to the System Management UnitHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.