Database/Firmware, BMC & network fabric
Intel processors with SGX (EDECCSSA leaf): Improper access control on the EDECCSSA user leaf function lets
CVSS 6.5CVE-2024-36293Firmware, BMC & network fabriccurated
Impact
Improper access control on the EDECCSSA user leaf function lets an authenticated local user deny SGX service. EDECCSSA is the SGX2 instruction used for in-enclave exception handling, so this is reachable from ordinary enclave-adjacent code.
Who can reach it
Local authenticated user on an SGX-enabled host.
What to do
Microcode update and reboot; late-loadable at boot without an OEM BIOS release. Re-attest afterwards.
References
Related entries
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel): The IPsec offload worker does not check the xfrmCVE-2024-49953 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel)Medium
- Intel PCIe Switch firmware package and LED mode toggle tool before version MR4_1.0b1: Improper access controlCVE-2025-24323 · Intel PCIe Switch firmware package and LED mode toggle tool before version MR4_1.0b1Medium
- Intel Ethernet Network Adapter E810 (100GbE) firmware: Out-of-bounds read in 100GbE E810 firmware reachableCVE-2025-32003 · Intel Ethernet Network Adapter E810 (100GbE) firmwareMedium
- Dell SmartFabric OS10 (XML external entity): XXE in SmartFabric OS10 before 10.6.0.5, reachable remotelyCVE-2025-36608 · Dell SmartFabric OS10 (XML external entity)Medium
- Linux kernel (drivers/infiniband/core): Bursts of network neighbour updates crash the node. Each event re-initializes aCVE-2025-37772 · Linux kernel (drivers/infiniband/core)Medium
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel): All IPsec offload objects on a physical function shareCVE-2026-23441 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en_accel)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.