Database/Firmware, BMC & network fabric
Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance is
Impact
TeeJam: shows that SGX's cache-based side-channel resistance is weaker than assumed at sub-cacheline granularity, enabling practical key recovery against enclave implementations previously believed to be constant-time. Operationally this matters because 'we run it in an enclave' is often the entire argument for putting a key on a shared host.
Who can reach it
Local code on the same machine as the victim enclave, with the scheduling control a privileged host has.
What to do
No single patch - mitigation lives in the enclave software (constant-time implementations hardened at sub-cacheline granularity) and in keeping the SGX SDK/PSW current. Operator action is to require enclave vendors to state which side-channel hardening they apply, and to keep microcode and PSW at current TCB so attestation reflects reality.
References
Related entries
- Intel SGX (cache side channel on sub-cacheline access): TeeJam: shows that SGX's cache-based side-channel resistance isNCVD-2024-006-intel-sgx-cache-side-channel-on · Intel SGX (cache side channel on sub-cacheline access)Unscored
- Platform attestation as an operational control (fTPM vs discrete TPM trust): Design-level: on most GPU servers the TPMNCVD-2024-001-platform-attestation-as-an-opera · Platform attestation as an operational control (fTPM vs discrete TPM trust)Unscored
- Intel processors (Indirect Branch Predictor structure): Indirector: reverse-engineering the Indirect Branch PredictorNCVD-2024-002-intel-processors-indirect-branch · Intel processors (Indirect Branch Predictor structure)Unscored
- Intel processors (Indirect Branch Predictor structure): Indirector: reverse-engineering the Indirect Branch PredictorNCVD-2024-007-intel-processors-indirect-branch · Intel processors (Indirect Branch Predictor structure)Unscored
- ASPEED AST2600 / AST2700 hardware root of trust in OpenBMC builds: AST2600 has a fuse-backed secure boot that verifiesNCVD-2025-001-aspeed-ast2600-ast2700-hardware · ASPEED AST2600 / AST2700 hardware root of trust in OpenBMC buildsUnscored
- Intel SGX / DDR4 memory bus (physical interposer): WireTap: a low-cost passive DDR4 interposer reads the memory bus ofNCVD-2025-001-intel-sgx-ddr4-memory-bus-physic · Intel SGX / DDR4 memory bus (physical interposer)Unscored
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.