PT-2021-15139 · Google · Asylo

Kang Li

+3

·

Published

2021-08-02

·

Updated

2021-08-10

·

CVE-2021-22552

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Asylo versions up to 0.6.1
Description The issue allows an untrusted attacker to bypass validation by passing a syscall number in MessageReader that is then used by sysno(), potentially enabling the attacker to read memory from within the secure enclave.
Recommendations Update to Asylo 0.6.3 or later to resolve the issue.

Exploit

Fix

Buffer Over-read

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-22552

Affected Products

Asylo