PT-2023-26250 · Intel · Intel Sgx

Andreas Kogler

+5

·

Publicado

2023-12-29

·

Atualizado

2024-01-17

·

CVE-2023-38023

CVSS v3.1

5.5

Média

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SCONE Confidential Computing Platform versions prior to 5.8.0
Description An issue was discovered in the SCONE Confidential Computing Platform, where the lack of pointer-alignment logic in scone dispatch and other entry functions allows a local attacker to access unauthorized information, also known as an "AEPIC Leak". This issue affects the Intel SGX platform.
Recommendations For versions prior to 5.8.0, update to version 5.8.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the scone dispatch function and other affected entry functions until a patch is available.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2023-38023
GHSA-V3VM-9H66-WM76

Produtos afetados

Intel Sgx