CVE-2023-38021
30.12.2023, 03:15
An issue was discovered in Fortanix EnclaveOS Confidential Computing Manager (CCM) Platform before 3.32 for Intel SGX. Lack of pointer-alignment validation logic in entry functions allows a local attacker to access unauthorized information. This relates to the enclave_ecall function and system call layer.Enginsight
Vendor | Product | Version |
---|---|---|
fortanix | confidential_computing_manager | 𝑥 < 3.32 |
𝑥
= Vulnerable software versions
References