Database/Firmware, BMC & network fabric
Intel SGX SDK (Edger8r code generator): The Edger8r tool generates the trusted/untrusted bridge code for enclaves
CVSS 3.9CVE-2025-32004Firmware, BMC & network fabriccurated
Impact
The Edger8r tool generates the trusted/untrusted bridge code for enclaves; an input-validation flaw here means the generated bridge itself can be unsafe. Every enclave built with the affected SDK inherits the problem.
Who can reach it
Local authenticated user against an enclave built with the affected generator.
What to do
Rebuild enclaves with a fixed SGX SDK and re-attest. Vendor-side fix; no operator reboot but also nothing you can patch yourself.
References
Related entries
- Intel SGX DCAP for Windows: Input-validation flaw in the Windows DCAP components allowing local information disclosureCVE-2023-42776 · Intel SGX DCAP for WindowsLow
- AMD processors - speculative inference of control registers despite UMIP: Part of the Transient Scheduler Attacks batchCVE-2024-36348 · AMD processors - speculative inference of control registers despite UMIPLow
- AMD processors - speculative inference of TSC_AUX when reads are disabled: Sibling of the other Transient SchedulerCVE-2024-36349 · AMD processors - speculative inference of TSC_AUX when reads are disabledLow
- Hitachi VSP One Block: firmware update path does not validate the image before applying itCVE-2025-0824 · Hitachi Virtual Storage Platform One Block 23/24/26/28 (firmware update validation)Low
- Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledCVE-2026-0995 · Arm C1-Pro before r1p2; Trusted Firmware-A v2.10 and later on multi-core configurations with the CME complex enabledLow
- EDK II NetworkPkg (IScsiDxe, Ready-To-Transfer PDU handling): A malicious iSCSI target sends a crafted R2T PDUCVE-2025-2295 · EDK II NetworkPkg (IScsiDxe, Ready-To-Transfer PDU handling)Low
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.