Database/Firmware, BMC & network fabric
Intel processors with SGX (shared resource isolation): Improper isolation of shared microarchitectural resources lets a
CVSS 6.0CVE-2022-38090Firmware, BMC & network fabriccurated
Impact
Improper isolation of shared microarchitectural resources lets a privileged user extract information from SGX enclaves. Another TCB-recovery event for anyone selling enclave-backed confidentiality.
Who can reach it
Privileged local access on the host.
What to do
Microcode update and re-attestation. Late-loadable microcode plus reboot; no OEM BIOS strictly required for the microcode component.
References
Related entries
- Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit): The dynamic-counter netlink setter bounded itsCVE-2022-49199 · Linux kernel RDMA core netlink (nldev_stat_set_counter_dynamic_doit)Medium
- AMD SEV-SNP firmware, guest teardown / UMC key seed handling: TENANT HANDOFF FAILURECVE-2023-31355 · AMD SEV-SNP firmware, guest teardown / UMC key seed handlingMedium
- AMI MegaRAC SPx (IPMI handler): Arbitrary file upload and download through the BMC's IPMI handlerCVE-2023-34342 · AMI MegaRAC SPx (IPMI handler)Medium
- Intel TDX module: The TDX module is the software that stands between the host/VMM and every confidential VM on the boxCVE-2023-47855 · Intel TDX moduleMedium
- Cisco NX-OS CLI: Command injection giving root on the switch's underlying OS from an admin CLI sessionCVE-2024-20399 · Cisco NX-OS CLIMedium
- Intel TDX SEAM loader (Seamldr): Sensitive information is not cleared before a resource is reused in the SEAM loaderCVE-2024-21850 · Intel TDX SEAM loader (Seamldr)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.