PT-2020-20378 · Google · Asylo

Kang Li

+3

·

Published

2020-12-15

·

Updated

2020-12-17

·

CVE-2020-8940

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Asylo versions up to 0.6.0
Description An arbitrary memory read issue allows an untrusted attacker to make a call to enc untrusted recvmsg using an attacker-controlled result parameter. The size parameter is unchecked, allowing the attacker to read memory locations outside of the intended buffer size, including memory addresses within the secure enclave.
Recommendations For Asylo versions up to 0.6.0, upgrade or apply changes past commit fa6485c5d16a7355eab047d4a44345a73bc9131e to resolve the issue. As a temporary workaround, consider restricting access to the enc untrusted recvmsg function until a patch is available.

Fix

Out of bounds Read

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-8940

Affected Products

Asylo